Cms Made Simple · Cms Made Simple · CVE-2019-17629
**Name of the Vulnerable Software and Affected Versions**
CMS Made Simple versions 2.2.11
**Description**
The issue allows for stored XSS by an admin via a crafted image filename on the "file manager > upload images" screen.
**Recommendations**
For version 2.2.11, update to a newer version that contains a fix for this issue.