packetstormsecurity.com
http://packetstormsecurity.com/files/159434/CMS-Made-Simple-2.2.14-Cross-Site-Scripting.html CVE-2020-24860
MEDIUM
CMS Made Simple 2.2.14 - Persistent Cross-Site Scripting (Authenticated)
Record summary
CVE-2020-24860 has a selected CVSS score of 5.4 (medium); EIP currently links 1 catalogued exploit.
Description
CMS Made Simple 2.2.14 allows an authenticated user with access to the Content Manager to edit content and put persistent XSS payload in the affected text fields. The user can get cookies from every authenticated user who visits the website.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBCMS Made Simple 2.2.14 - Persistent Cross-Site Scripting (Authenticated)ExploitDB exploitby Roel van BeurdenNot analyzed1 file
References
5nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-24860 cmsmadesimple.org
https://www.cmsmadesimple.org/ exploit-db.com
https://www.exploit-db.com/exploits/48851 youtube.com
https://www.youtube.com/watch?v=M6D7DmmjLak&t=22s