CVE-2021-28935

MEDIUM

CMS Made Simple 2.2.15 - Authenticated Cross-Site Scripting via Title Field

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2021-28935. PoCs published by bt0.

AI-analyzed exploit summary This exploit demonstrates a reflected XSS vulnerability in CMS Made Simple 2.2.15 via the 'title' field in the admin panel's My Preferences section. The payloads provided can execute arbitrary JavaScript in the context of the admin user's session.

Description

CMS Made Simple (CMSMS) 2.2.15 allows authenticated XSS via the /admin/addbookmark.php script through the Site Admin > My Preferences > Title field.

Exploits (1)

exploitdb WORKING POC
by bt0 · textwebappsphp
https://www.exploit-db.com/exploits/49793

This exploit demonstrates a reflected XSS vulnerability in CMS Made Simple 2.2.15 via the 'title' field in the admin panel's My Preferences section. The payloads provided can execute arbitrary JavaScript in the context of the admin user's session.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: CMS Made Simple 2.2.15
Auth required
Prerequisites: Admin access to the CMS Made Simple panel
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Issue Tracking, Vendor Advisory x_refsource_misc
http://dev.cmsmadesimple.org/bug/view/12432

Scores

CVSS v3 5.4
EPSS 0.0157
EPSS Percentile 72.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
cmsmadesimple/cms_made_simple 2.2.15
Published Mar 30, 2021
Tracked Since Feb 18, 2026