CVE-2020-23240
- EPSS 0.31%
- Veröffentlicht 26.07.2021 21:15:16
- Zuletzt bearbeitet 21.11.2024 05:13:39
Cross Site Scripting (XSS) vulnerablity in CMS Made Simple 2.2.14 via the Logic field in the Content Manager feature.
CVE-2020-23241
- EPSS 0.31%
- Veröffentlicht 26.07.2021 21:15:16
- Zuletzt bearbeitet 21.11.2024 05:13:40
Cross Site Scripting (XSS) vulnerability in CMS Made Simple 2.2.14 in "Extra" via 'News > Article" feature.
CVE-2020-36416
- EPSS 0.28%
- Veröffentlicht 02.07.2021 18:15:09
- Zuletzt bearbeitet 21.11.2024 05:29:27
A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Create a new Design" parameter under the "Designs" module.
CVE-2020-36408
- EPSS 0.31%
- Veröffentlicht 02.07.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:29:26
A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Add Shortcut" parameter under the "Manage Shortcuts" module.
CVE-2020-36409
- EPSS 0.28%
- Veröffentlicht 02.07.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:29:26
A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Add Category" parameter under the "Categories" module.
CVE-2020-36410
- EPSS 0.28%
- Veröffentlicht 02.07.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:29:26
A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Email address to receive notification of news submission" parameter...
CVE-2020-36411
- EPSS 0.28%
- Veröffentlicht 02.07.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:29:26
A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Path for the {page_image} tag:" or "Path for thumbnail field:" para...
CVE-2020-36412
- EPSS 0.28%
- Veröffentlicht 02.07.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:29:26
A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Search Text" field under the "Admin Search" module.
CVE-2020-36413
- EPSS 0.28%
- Veröffentlicht 02.07.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:29:27
A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Exclude these IP addresses from the "Site Down" status" parameter u...
CVE-2020-36414
- EPSS 0.32%
- Veröffentlicht 02.07.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:29:27
A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "URL (slug)" or "Extra" fields under the "Add Article" feature.