PT-2026-5562 · Unknown · Simple-Cms
Published
2026-02-01
·
Updated
2026-02-01
·
CVE-2021-47917
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Simple CMS version 2.1
Description
Simple CMS version 2.1 contains a persistent cross-site scripting issue in user input parameters. Remote attackers can inject malicious script code through the
newUser and editUser modules. Successful exploitation allows the injection of persistent scripts that execute on the user list preview, potentially leading to session hijacking and application manipulation.Recommendations
Update Simple CMS to a newer version that addresses this issue. As a temporary workaround, consider restricting or disabling the
newUser and editUser modules until a patch is available.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simple-Cms