Lucene search

K
nvd[email protected]NVD:CVE-2024-27625
HistoryMar 05, 2024 - 2:15 p.m.

CVE-2024-27625

2024-03-0514:15:49
web.nvd.nist.gov
cross site scripting
admin panel
sanitization

6.1 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.2%

CMS Made Simple Version 2.2.19 is vulnerable to Cross Site Scripting (XSS). This vulnerability resides in the File Manager module of the admin panel. Specifically, the issue arises due to inadequate sanitization of user input in the β€œNew directory” field.

6.1 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.2%

Related for NVD:CVE-2024-27625