Full Disclosure mailing list archives
Multiple Issues in CMS Made Simple
From: Ziyahan Albeniz <ziyahan () netsparker com>
Date: Mon, 27 Nov 2017 14:56:22 +0300
Hi, Glad to inform you two different issue we reported in CMS Made Simple Script. Here are the details: Affected Software : CMS Made Simple Affected Versions: Tested on 2.1.6 Vendor Homepage : http://www.cmsmadesimple.org/ Vulnerability Type : Server-Side Template Injection Severity : Important Status : Fixed CVE-ID : CVE-2017-16783 CVSS Base Score (3.0) :9.8 CVSS Vector String(3.0): AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Netsparker Advisory Reference : NS-17-32 Detailed write up: https://www.netsparker.com/blog/web-security/exploiting-ssti-and-xss-in-cms-made-simple/ For more information: https://www.netsparker.com/web-applications-advisories/ns-17-032-server-side-template-injection-vulnerability-in-cms-made-simple/ Affected Software : CMS Made Simple Affected Versions: 2.2.2 Homepage : http://www.cmsmadesimple.org/ Vulnerability Type : Reflected XSS Severity : Important Status : Fixed CVE-ID : CVE-2017-16784 CVSS Base Score (3.0) :6.3 CVSS Vector String(3.0): AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L Netsparker Advisory Reference : NS-17-31 Proof of concept write up: https://www.netsparker.com/blog/web-security/exploiting-ssti-and-xss-in-cms-made-simple/ Fore more information: https://www.netsparker.com/web-applications-advisories/ns-17-031-reflected-xss-vulnerability-in-cms-made-simple/ -- Regards, Ziyahan Albeniz Security Researcher | Netsparker Web Application Security Scanner Follow us on: Twitter <https://twitter.com/netsparker> | LinkedIn <https://www.linkedin.com/company/netsparker-ltd> | Facebook <https://facebook.com/netsparker> | Google Plus <https://plus.google.com/117335596680718226953/posts> _______________________________________________ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/
Current thread:
- Multiple Issues in CMS Made Simple Ziyahan Albeniz (Nov 28)
