Stored XSS Vulnerability in CMS Made Simple 2.2.14 via Crafted Payload in Exclude IP Addresses Parameter

Stored XSS Vulnerability in CMS Made Simple 2.2.14 via Crafted Payload in Exclude IP Addresses Parameter

CVE-2020-36413 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Exclude these IP addresses from the "Site Down" status" parameter under the "Maintenance Mode" module.

Learn more about our Web App Pen Testing.