PT-2026-25635 · Undefined · Undefined

Feioklucy

·

Publicado

2026-03-16

·

Atualizado

2026-03-16

·

CVE-2026-4225

CVSS v2.0

3.3

Baixa

VetorAV:N/AC:L/Au:M/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions CMS Made Simple versions up to 2.2.21
Description A security issue exists in CMS Made Simple that allows for cross site scripting. The issue is located in the User Management Module, specifically within the admin/listusers.php file. Manipulation of the Message argument can trigger the flaw, and the attack can be carried out remotely. The exploit for this issue has been publicly released.
Recommendations Versions prior to 2.2.21 should be updated.

Exploit

Correção

XSS

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-4225

Produtos afetados

Undefined