CVE-2020-24860

MEDIUM

Cmsmadesimple Cms Made Simple - XSS

Title source: rule
STIX 2.1

Description

CMS Made Simple 2.2.14 allows an authenticated user with access to the Content Manager to edit content and put persistent XSS payload in the affected text fields. The user can get cookies from every authenticated user who visits the website.

Exploits (1)

exploitdb WRITEUP
by Roel van Beurden · textwebappsphp
https://www.exploit-db.com/exploits/48851

Scores

CVSS v3 5.4
EPSS 0.0063
EPSS Percentile 70.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
cmsmadesimple/cms_made_simple 2.2.14
Published Oct 01, 2020
Tracked Since Feb 18, 2026