PT-2018-15127 · Getsimple · Getsimple Cms

Published

2018-12-31

·

Updated

2019-02-25

·

CVE-2018-19845

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions GetSimple CMS version 3.3.12
Description The issue is related to Stored XSS in the admin/edit.php page, specifically via the post-menu parameter.
Recommendations For GetSimple CMS version 3.3.12, avoid using the post-menu parameter in the admin/edit.php page until the issue is resolved. As a temporary workaround, consider restricting access to the admin/edit.php page to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-19845

Affected Products

Getsimple Cms