CVE-2024-32345: XSS
A cross-site scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Configuration parameter under the Language section.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-32345?
CVE-2024-32345 is classified as a medium severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2024-32345?
To fix CVE-2024-32345, ensure that input validation and output encoding are applied to the Configuration parameter in the Language section.
What types of attacks does CVE-2024-32345 allow?
CVE-2024-32345 allows attackers to execute arbitrary web scripts or HTML through cross-site scripting.
Which versions of CMSimple are affected by CVE-2024-32345?
CVE-2024-32345 affects CMSimple version 5.15.
How can I determine if my CMSimple installation is vulnerable to CVE-2024-32345?
You can determine if your CMSimple installation is vulnerable to CVE-2024-32345 by checking if you are running version 5.15 and if the Configuration parameter in the Language section is not properly sanitized.