Show filters
17 Total Results
Displaying 11-17 of 17
Sort by:
Attacker Value
Unknown
CVE-2020-36411
Disclosure Date: July 02, 2021 (last updated February 22, 2025)
A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Path for the {page_image} tag:" or "Path for thumbnail field:" parameters under the "Content Editing Settings" module.
0
Attacker Value
Unknown
CVE-2020-36415
Disclosure Date: July 02, 2021 (last updated February 22, 2025)
A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Create a new Stylesheet" parameter under the "Stylesheets" module.
0
Attacker Value
Unknown
CVE-2020-36412
Disclosure Date: July 02, 2021 (last updated February 22, 2025)
A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Search Text" field under the "Admin Search" module.
0
Attacker Value
Unknown
CVE-2020-27377
Disclosure Date: June 01, 2021 (last updated February 22, 2025)
A cross-site scripting (XSS) vulnerability was discovered in the Administrator panel on the 'Setting News' module on CMS Made Simple 2.2.14 which allows an attacker to execute arbitrary web scripts.
0
Attacker Value
Unknown
CVE-2020-24860
Disclosure Date: October 01, 2020 (last updated February 22, 2025)
CMS Made Simple 2.2.14 allows an authenticated user with access to the Content Manager to edit content and put persistent XSS payload in the affected text fields. The user can get cookies from every authenticated user who visits the website.
0
Attacker Value
Unknown
CVE-2020-17462
Disclosure Date: August 14, 2020 (last updated February 21, 2025)
CMS Made Simple 2.2.14 allows Authenticated Arbitrary File Upload because the File Manager does not block .ptar files, a related issue to CVE-2017-16798.
0
Attacker Value
Unknown
CVE-2020-14926
Disclosure Date: June 19, 2020 (last updated February 21, 2025)
CMS Made Simple 2.2.14 allows XSS via a Search Term to the admin/moduleinterface.php?mact=ModuleManager page.
0