PT-2026-5562 · Unknown · Simple-Cms
CVE-2021-47917
·
Publicado
2026-02-01
·
Atualizado
2026-02-01
CVSS v3.1
6.4
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Simple CMS version 2.1
Description
Simple CMS version 2.1 contains a persistent cross-site scripting issue in user input parameters. Remote attackers can inject malicious script code through the
newUser and editUser modules. Successful exploitation allows the injection of persistent scripts that execute on the user list preview, potentially leading to session hijacking and application manipulation.Recommendations
Update Simple CMS to a newer version that addresses this issue. As a temporary workaround, consider restricting or disabling the
newUser and editUser modules until a patch is available.Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Simple-Cms