ZeroHour

CVE-2024-27625

PoC
CVSS 3.1
4.8 medium
EPSS
<1%p35
Published
()
Modified
Description

CMS Made Simple Version 2.2.19 is vulnerable to Cross Site Scripting (XSS). This vulnerability resides in the File Manager module of the admin panel. Specifically, the issue arises due to inadequate sanitization of user input in the "New directory" field.

Vendors
cmsmadesimple
Products
cms made simple
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.