SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-24861

GetSimple CMS 3.3.16 allows in parameter 'permalink' on the Settings page persistent Cross Site Scripting which is executed when you create and open a new page

MEDIUM 5.4EPSS 0.88%

Does this matter?

Lower severity and a low EPSS score (0.88%). Track it; it rarely justifies an emergency change on its own.

Description

GetSimple CMS 3.3.16 allows in parameter 'permalink' on the Settings page persistent Cross Site Scripting which is executed when you create and open a new page

CVSS 3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS
0.88% probability · 57th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
get-simple/getsimple cms
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.