CVE-2023-43356: XSS
Published Oct 20, 2023
·Updated
Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Global Meatadata parameter in the Global Settings Menu component.
Affected Software
1 affected component
CMSmadesimple CMS Made Simple=2.2.18
Event History
Oct 20, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
10:15 PM
Description
Frequently Asked Questions
1
What is CVE-2023-43356?
CVE-2023-43356 is a Cross Site Scripting (XSS) vulnerability in CMSmadesimple v.2.2.18.
2
How severe is CVE-2023-43356?
CVE-2023-43356 has a severity level of 5.4, which is considered medium.
3
How can a local attacker exploit CVE-2023-43356?
A local attacker can exploit CVE-2023-43356 by executing arbitrary code using a crafted script in the Global Metadata parameter of the Global Settings Menu component.
4
What software versions are affected by CVE-2023-43356?
CMSmadesimple v.2.2.18 is the affected version.
5
Is there a fix available for CVE-2023-43356?
Updating CMSmadesimple to a version beyond 2.2.18 will fix CVE-2023-43356.