CVE-2023-51246: XSS
A Cross Site Scripting (XSS) vulnerability in GetSimple CMS 3.3.16 exists when using Source Code Mode as a backend user to add articles via the /admin/edit.php page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-51246?
CVE-2023-51246 is classified as a Cross Site Scripting (XSS) vulnerability, which can lead to unauthorized access and data exposure.
How do I fix CVE-2023-51246?
To fix CVE-2023-51246, update to a patched version of GetSimple CMS that addresses the XSS vulnerability.
What software is affected by CVE-2023-51246?
CVE-2023-51246 specifically affects GetSimple CMS version 3.3.16.
What actions can an attacker perform using CVE-2023-51246?
An attacker can exploit CVE-2023-51246 to inject malicious scripts into the articles added via the /admin/edit.php page, potentially targeting other users.
Is there a workaround for CVE-2023-51246?
A potential workaround for CVE-2023-51246 is to avoid using the Source Code Mode feature when editing articles until a fix is applied.