First published: Mon Jan 08 2024(Updated: )
A Cross Site Scripting (XSS) vulnerability in GetSimple CMS 3.3.16 exists when using Source Code Mode as a backend user to add articles via the /admin/edit.php page.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Getsimple CMS | =3.3.16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-51246 is classified as a Cross Site Scripting (XSS) vulnerability, which can lead to unauthorized access and data exposure.
To fix CVE-2023-51246, update to a patched version of GetSimple CMS that addresses the XSS vulnerability.
CVE-2023-51246 specifically affects GetSimple CMS version 3.3.16.
An attacker can exploit CVE-2023-51246 to inject malicious scripts into the articles added via the /admin/edit.php page, potentially targeting other users.
A potential workaround for CVE-2023-51246 is to avoid using the Source Code Mode feature when editing articles until a fix is applied.