Cross-site scripting in CMS Made Simple - CVE-2016-2784

 

Cross-site scripting in CMS Made Simple - CVE-2016-2784

Published: May 26, 2016 / Updated: August 9, 2020


Vulnerability identifier: #VU40264
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:P/U:Clear
CVE-ID: CVE-2016-2784
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: Public exploit is available
Vendor: cmsmadesimple.org
Affected software:
CMS Made Simple

Detailed vulnerability description

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

CMS Made Simple 2.x before 2.1.3 and 1.x before 1.12.2, when Smarty Cache is activated, allow remote attackers to conduct cache poisoning attacks, modify links, and conduct cross-site scripting (XSS) attacks via a crafted HTTP Host header in a request.


How to mitigate CVE-2016-2784

Install update from vendor's website.

Sources