MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS before 3.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to backup-edit.php; (2) title or (3) menu parameter to edit.php; or (4) path or (5) returnid parameter to filebrowser.php in admin/
Published Jan 2, 2020
6.1
MEDIUMCVSS 3.1
EPSS 1.06%
Description
Affected products
Remediation
References (3)
Change history (0)
No recorded changes yet.