CVE-2010-3882
CMS Made Simple <= 1.7.1 - Cross-Site Scripting via Multiple Input Modules
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in CMS Made Simple 1.7.1 and earlier allow remote attackers to inject arbitrary web script or HTML via input to the (1) Add Pages, (2) Add Global Content, (3) Edit Global Content, (4) Add Article, (5) Add Category, (6) Add Field Definition, or (7) Add Shortcut module.
References (2)
Core 2
Core References
Various Sources x_refsource_misc
http://security.bkis.com/multiple-vulnerabilities-in-cms-made-simple/
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/40031
Scores
EPSS
0.0026
EPSS Percentile
49.7%
Details
CWE
CWE-79
Status
published
Products (31)
cmsmadesimple/cms_made_simple
0.10
cmsmadesimple/cms_made_simple
0.10.3
cmsmadesimple/cms_made_simple
0.10.4
cmsmadesimple/cms_made_simple
0.11 (3 CPE variants)
cmsmadesimple/cms_made_simple
0.11.1
cmsmadesimple/cms_made_simple
0.11.2
cmsmadesimple/cms_made_simple
0.12 (3 CPE variants)
cmsmadesimple/cms_made_simple
0.12.1
cmsmadesimple/cms_made_simple
0.12.2
cmsmadesimple/cms_made_simple
0.13 beta1 (3 CPE variants)
... and 21 more
Published
Oct 08, 2010
Tracked Since
Feb 18, 2026