CVE-2023-43358: XSS
Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Title parameter in the News Menu component.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-43358?
CVE-2023-43358 is a Cross-Site Scripting vulnerability in CMSmadesimple v.2.2.18 that allows a local attacker to execute arbitrary code.
How does the vulnerability in CMSmadesimple v.2.2.18 work?
The vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code by injecting a crafted script into the Title parameter in the News Menu component.
What is the severity of CVE-2023-43358?
CVE-2023-43358 has a severity value of 5.4, which is considered medium.
Is there a fix available for CVE-2023-43358?
Yes, upgrading CMSmadesimple to a version that is not affected by the vulnerability will fix CVE-2023-43358.
Where can I find more information about CVE-2023-43358?
You can find more information about CVE-2023-43358 on the following references: [github.com/sromanhu/CMSmadesimple-Stored-XSS---News](github.com/sromanhu/CMSmadesimple-Stored-XSS---News), [github.com/sromanhu/CVE-2023-43358-CMSmadesimple-Stored-XSS---News](github.com/sromanhu/CVE-2023-43358-CMSmadesimple-Stored-XSS---News)