Vulnerabilities > CVE-2024-1529 - Unspecified vulnerability in Cmsmadesimple CMS Made Simple 2.2.14

047910
CVSS 6.1 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
LOW
Integrity impact
LOW
Availability impact
NONE
network
low complexity
cmsmadesimple

Summary

Vulnerability in CMS Made Simple 2.2.14, which does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /admin/adduser.php, in multiple parameters. This vulnerability could allow a remote attacker to send a specially crafted JavaScript payload to an authenticated user and partially take over their browser session.

Vulnerable Configurations

Part Description Count
Application
Cmsmadesimple
1