PT-2020-15845 · Getsimple · Getsimple Cms

Roel Van Beurden

·

Published

2020-10-01

·

Updated

2020-10-08

·

CVE-2020-24861

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions GetSimple CMS version 3.3.16
Description The issue concerns a persistent Cross Site Scripting (XSS) flaw. It occurs through the permalink parameter on the Settings page. The XSS is executed when creating and opening a new page.
Recommendations For GetSimple CMS version 3.3.16, update to a newer version that contains a fix for this issue. As a temporary workaround, consider restricting access to the Settings page to minimize the risk of exploitation. Avoid using the permalink parameter in the affected Settings page until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-24861

Affected Products

Getsimple Cms