CVE-2024-33424: XSS
Published May 1, 2024
·Updated
A cross-site scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Downloads parameter under the Language section.
Affected Software
2 affected components
CmSimple CMSimple
CmSimple CMSimple=5.15
Event History
May 1, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-33424?
The severity of CVE-2024-33424 is high due to its potential for allowing arbitrary web scripts or HTML execution.
2
How do I fix CVE-2024-33424?
To fix CVE-2024-33424, users should update to a patched version of CMSimple that addresses the XSS vulnerability.
3
Which version of CMSimple is affected by CVE-2024-33424?
CVE-2024-33424 specifically affects CMSimple version 5.15.
4
What type of vulnerability is CVE-2024-33424?
CVE-2024-33424 is a cross-site scripting (XSS) vulnerability.
5
How does CVE-2024-33424 exploit the CMSimple software?
CVE-2024-33424 allows attackers to execute arbitrary web scripts or HTML by injecting a crafted payload into the Downloads parameter.