Description
Vulnerability in CMS Made Simple 2.2.14, which does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /admin/adduser.php, in multiple parameters. This vulnerability could allow a remote attacker to send a specially crafted JavaScript payload to an authenticated user and partially take over their browser session.
No analysis available yet.
Remediation
Vendor Solution
There is no reported solution at this time.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-17277 | Vulnerability in CMS Made Simple 2.2.14, which does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /admin/adduser.php, in multiple parameters. This vulnerability could allow a remote attacker to send a specially crafted JavaScript payload to an authenticated user and partially take over their browser session. |
References
History
Wed, 26 Feb 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cmsmadesimple
Cmsmadesimple cms Made Simple |
|
| CPEs | cpe:2.3:a:cmsmadesimple:cms_made_simple:2.2.14:*:*:*:*:*:*:* | |
| Vendors & Products |
Cmsmadesimple
Cmsmadesimple cms Made Simple |
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-08-12T20:47:36.435Z
Reserved: 2024-02-15T11:01:42.277Z
Link: CVE-2024-1529
Updated: 2024-08-01T18:40:21.449Z
Status : Analyzed
Published: 2024-03-12T16:15:08.400
Modified: 2025-07-11T20:01:50.350
Link: CVE-2024-1529
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD