PT-2025-45332 · Unknown · Cmsimple Xh
Published
2025-11-06
·
Updated
2025-11-06
·
CVE-2025-63589
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
CMSimple XH version 1.8
Description
A reflected Cross-Site Scripting (XSS) issue exists in the
index.php router. The issue occurs because attacker-controlled path segments are not properly sanitized or encoded before being included in the generated HTML, specifically in navigation links, breadcrumbs, the search form action, and footer links. An attacker can inject a malicious string into the URL path, which is then reflected into multiple HTML elements, enabling the execution of arbitrary JavaScript code in a victim's browser when they access a specially crafted URL.Recommendations
Update to a newer version that contains a fix for this vulnerability.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cmsimple Xh