#VU40264 Cross-site scripting in CMS Made Simple - CVE-2016-2784 

 

#VU40264 Cross-site scripting in CMS Made Simple - CVE-2016-2784

Published: May 26, 2016 / Updated: August 9, 2020


Vulnerability identifier: #VU40264
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:P/U:Clear
CVE-ID: CVE-2016-2784
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: Public exploit is available
Vulnerable software:
CMS Made Simple
Software vendor:
cmsmadesimple.org

Description

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

CMS Made Simple 2.x before 2.1.3 and 1.x before 1.12.2, when Smarty Cache is activated, allow remote attackers to conduct cache poisoning attacks, modify links, and conduct cross-site scripting (XSS) attacks via a crafted HTTP Host header in a request.


Remediation

Install update from vendor's website.

External links