CMS Made Simple 2.2.10 has XSS via the moduleinterface.php Name field, which is reachable via an "Add a new Profile" action to the File Picker.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2019-03-24T21:31:47

Updated: 2024-08-04T22:10:09.398Z

Reserved: 2019-03-24T00:00:00

Link: CVE-2019-10017

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2019-03-24T22:29:00.347

Modified: 2019-07-18T16:27:06.033

Link: CVE-2019-10017

cve-icon Redhat

No data.