Stored XSS Vulnerability in CMS Made Simple 2.2.14 via Crafted Payload in Add Category Parameter

Stored XSS Vulnerability in CMS Made Simple 2.2.14 via Crafted Payload in Add Category Parameter

CVE-2020-36409 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Add Category" parameter under the "Categories" module.

Learn more about our Web App Pen Testing.