SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-24860

CMS Made Simple 2.2.14 allows an authenticated user with access to the Content Manager to edit content and put persistent XSS payload in the affected text fields.

MEDIUM 5.4EPSS 1.09%

Does this matter?

Lower severity and a low EPSS score (1.09%). Track it; it rarely justifies an emergency change on its own.

Description

CMS Made Simple 2.2.14 allows an authenticated user with access to the Content Manager to edit content and put persistent XSS payload in the affected text fields. The user can get cookies from every authenticated user who visits the website.

CVSS 3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS
1.09% probability · 63th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
cmsmadesimple/cms made simple
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.