Stored XSS Vulnerability in CMS Made Simple 2.2.14 via Crafted Payload in Email address to receive notification of news submission Parameter

Stored XSS Vulnerability in CMS Made Simple 2.2.14 via Crafted Payload in Email address to receive notification of news submission Parameter

CVE-2020-36410 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Email address to receive notification of news submission" parameter under the "Options" module.

Learn more about our Web App Pen Testing.