Cms Made Simple · Cms Made Simple · CVE-2020-13660
**Name of the Vulnerable Software and Affected Versions**
CMS Made Simple versions prior to 2.2.15
**Description**
The issue allows for cross-site scripting (XSS) attacks through a crafted File Picker profile name.
**Recommendations**
For CMS Made Simple versions prior to 2.2.15, update to version 2.2.15 or later to resolve the issue.