PT-2020-7349 · Unknown · Getsimple Cms
Published
2020-01-02
·
Updated
2020-01-13
·
CVE-2013-1420
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
GetSimple CMS versions prior to 3.2.1
Description:
The issue allows remote attackers to inject arbitrary web script or HTML. This can be achieved via several parameters, including the
id parameter to "backup-edit.php", the title or menu parameter to "edit.php", or the path or returnid parameter to "filebrowser.php" in the admin directory.Recommendations:
For versions prior to 3.2.1, update to version 3.2.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the affected admin pages, specifically "backup-edit.php", "edit.php", and "filebrowser.php", until the update is applied. Avoid using the vulnerable parameters
id, title, menu, path, and returnid in the respective API endpoints until the issue is resolved.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Getsimple Cms