PT-2022-16326 · Unknown · Cms Made Simple
Fuzzyap1
·
Published
2022-02-28
·
Updated
2022-03-08
·
CVE-2022-23907
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
CMS Made Simple version 2.2.15
Description
A reflected cross-site scripting (XSS) issue was found, which can be exploited via the
m1 fmmessage parameter.Recommendations
For CMS Made Simple version 2.2.15, update to a version that fixes this issue to prevent exploitation.
As a temporary workaround, consider restricting access to the parameter
m1 fmmessage to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cms Made Simple