cve/2024/CVE-2024-27625.md

20 lines
921 B
Markdown
Raw Normal View History

2024-05-25 21:48:12 +02:00
### [CVE-2024-27625](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27625)
![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen)
### Description
CMS Made Simple Version 2.2.19 is vulnerable to Cross Site Scripting (XSS). This vulnerability resides in the File Manager module of the admin panel. Specifically, the issue arises due to inadequate sanitization of user input in the "New directory" field.
### POC
#### Reference
- https://packetstormsecurity.com/files/177243/CMS-Made-Simple-2.2.19-Cross-Site-Scripting.html
2024-06-09 00:33:16 +00:00
- https://packetstormsecurity.com/files/177243/CMS-Made-Simple-2.2.19-Cross-Site-Scripting.html
2024-05-25 21:48:12 +02:00
#### Github
- https://github.com/capture0x/My-CVE
- https://github.com/fkie-cad/nvd-json-data-feeds