PT-2026-41438 · Cms Made Simple · Cms Made Simple

Eshan Singh

·

Published

2026-05-16

·

Updated

2026-05-16

·

CVE-2020-37238

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
CMS Made Simple 2.2.15 contains a stored cross-site scripting vulnerability that allows authenticated users with Content Manager access to inject malicious scripts through SVG file uploads. Attackers can upload SVG files containing embedded JavaScript to the file manager, which executes when other authenticated users access the uploaded file, enabling cookie theft and session hijacking.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2020-37238

Affected Products

Cms Made Simple