CVE-2024-32344: XSS
Published Apr 17, 2024
·Updated
A cross-site scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Edit parameter under the Language section.
Affected Software
1 affected component
CmSimple CMSimple
Event History
Apr 17, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-32344?
CVE-2024-32344 is classified as a medium-severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2024-32344?
To fix CVE-2024-32344, update CMSimple to the latest version that addresses this XSS vulnerability.
3
What impact does CVE-2024-32344 have on CMSimple users?
CVE-2024-32344 allows attackers to execute arbitrary scripts, potentially compromising user data and website integrity.
4
Which version of CMSimple is affected by CVE-2024-32344?
CVE-2024-32344 affects CMSimple version 5.15.
5
Where does CVE-2024-32344 occur in CMSimple?
CVE-2024-32344 occurs in the Settings menu under the Edit parameter in the Language section.