MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in CMS Made Simple 1.7.1 and earlier allow remote attackers to inject arbitrary web script or HTML via input to the (1) Add Pages, (2) Add Global Content, (3) Edit Global Content, (4) Add Article, (5) Add Category, (6) Add Field Definition, or (7) Add Shortcut module
Published Oct 8, 2010
4.3
MEDIUMCVSS 2.0
EPSS 0.84%
Description
Multiple cross-site scripting (XSS) vulnerabilities in CMS Made Simple 1.7.1 and earlier allow remote attackers to inject arbitrary web script or HTML via input to the (1) Add Pages, (2) Add Global Content, (3) Edit Global Content, (4) Add Article, (5) Add Category, (6) Add Field Definition, or (7) Add Shortcut module.
Affected products
No data.
OR
- ≤ 1.7.1
- 0.10
- 0.10.3
- 0.10.4
- 0.11
- 0.11
- 0.11
- 0.11.1
- 0.11.2
- 0.12
- 0.12
- 0.12
- 0.12.1
- 0.12.2
- 0.13
- 0.13
- 0.13
- 1.0
- 1.0
- 1.0
- 1.0
- 1.0
- 1.0
- 1.0
- 1.0.1
- 1.0.2
- 1.0.3
- 1.0.4
- 1.0.5
- 1.0.6
- 1.0.7
- 1.0.8
- 1.1
- 1.1
- 1.1
- 1.1
- 1.1.1
- 1.1.2
- 1.1.3.1
- 1.1.4.1
- 1.2
- 1.2
- 1.2
- 1.2
- 1.2
- 1.2.1
- 1.2.2
- 1.2.3
- 1.2.4
- 1.2.5
- 1.3
- 1.3
- 1.3
- 1.3.1
- 1.4
- 1.4
- 1.4
- 1.4.1
- 1.5
- 1.5
- 1.5.1
- 1.5.2
- 1.5.3
- 1.5.4
- 1.6
- 1.6.1
- 1.6.2
- 1.6.3
- 1.6.4
- 1.6.5
- 1.6.6
- 1.6.7
- 1.6.8
- 1.7
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- http://secunia.com/advisories/40031 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://security.bkis.com/multiple-vulnerabilities-in-cms-made-simple/ x_refsource_MISC
| Link | Providers | Tags |
|---|---|---|
| http://secunia.com/advisories/40031 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://security.bkis.com/multiple-vulnerabilities-in-cms-made-simple/ | x_refsource_MISC |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 8, 2010
Updated Sep 16, 2024
Reserved Oct 8, 2010
Link CVE-2010-3882
CISA Vulnrichment
Updated n/a