VulnerabilityModified
CVE-2020-24861
GetSimple CMS 3.3.16 allows in parameter 'permalink' on the Settings page persistent Cross Site Scripting which is executed when you create and open a new page
MEDIUM 5.4EPSS 0.88%
Does this matter?
Lower severity and a low EPSS score (0.88%). Track it; it rarely justifies an emergency change on its own.
Description
GetSimple CMS 3.3.16 allows in parameter 'permalink' on the Settings page persistent Cross Site Scripting which is executed when you create and open a new page
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.88% probability · 57th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- get-simple/getsimple cms
- Source
- cve@mitre.org
References
- http://get-simple.infoProduct
- https://www.exploit-db.com/exploits/48850Exploit, Third Party Advisory, VDB Entry
- https://www.youtube.com/watch?v=8IMfD5KGt_UExploit, Third Party Advisory
- http://get-simple.infoProduct
- https://www.exploit-db.com/exploits/48850Exploit, Third Party Advisory, VDB Entry
- https://www.youtube.com/watch?v=8IMfD5KGt_UExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.