Description
CMS Made Simple version 2.2.14, does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /admin/moduleinterface.php, in multiple parameters. This vulnerability could allow a remote attacker to send a specially crafted JavaScript payload to an authenticated user and partially hijack their browser session.
No analysis available yet.
Remediation
Vendor Solution
There is no reported solution at this time.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-17276 | CMS Made Simple version 2.2.14, does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /admin/moduleinterface.php, in multiple parameters. This vulnerability could allow a remote attacker to send a specially crafted JavaScript payload to an authenticated user and partially hijack their browser session. |
References
History
Wed, 26 Feb 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cmsmadesimple
Cmsmadesimple cms Made Simple |
|
| CPEs | cpe:2.3:a:cmsmadesimple:cms_made_simple:2.2.14:*:*:*:*:*:*:* | |
| Vendors & Products |
Cmsmadesimple
Cmsmadesimple cms Made Simple |
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-08-01T18:40:21.390Z
Reserved: 2024-02-15T11:01:41.642Z
Link: CVE-2024-1528
Updated: 2024-08-01T18:40:21.390Z
Status : Analyzed
Published: 2024-03-12T16:15:08.200
Modified: 2025-02-26T15:15:08.143
Link: CVE-2024-1528
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD