CVE-2021-28935
MEDIUMCMS Made Simple 2.2.15 - Authenticated Cross-Site Scripting via Title Field
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-28935. PoCs published by bt0.
AI-analyzed exploit summary This exploit demonstrates a reflected XSS vulnerability in CMS Made Simple 2.2.15 via the 'title' field in the admin panel's My Preferences section. The payloads provided can execute arbitrary JavaScript in the context of the admin user's session.
Description
CMS Made Simple (CMSMS) 2.2.15 allows authenticated XSS via the /admin/addbookmark.php script through the Site Admin > My Preferences > Title field.
Exploits (1)
This exploit demonstrates a reflected XSS vulnerability in CMS Made Simple 2.2.15 via the 'title' field in the admin panel's My Preferences section. The payloads provided can execute arbitrary JavaScript in the context of the admin user's session.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N