Stored XSS Vulnerability in CMS Made Simple 2.2.14 via Crafted Payload in Add Shortcut Parameter

Stored XSS Vulnerability in CMS Made Simple 2.2.14 via Crafted Payload in Add Shortcut Parameter

CVE-2020-36408 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Add Shortcut" parameter under the "Manage Shortcuts" module.

Learn more about our Web App Pen Testing.