CVE-2013-3929

Cross-site scripting (XSS) vulnerability in admin/editevent.php in CMS Made Simple (CMSMS) 1.11.9 allows remote authenticated users with the "Modify Events" permission to inject arbitrary web script or HTML via the handler parameter.
References
Link Resource
http://secunia.com/advisories/53920 Vendor Advisory
http://secunia.com/advisories/53920 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:cmsmadesimple:cms_made_simple:1.11.9:*:*:*:*:*:*:*

History

21 Nov 2024, 01:54

Type Values Removed Values Added
References () http://secunia.com/advisories/53920 - Vendor Advisory () http://secunia.com/advisories/53920 - Vendor Advisory

Information

Published : 2013-12-09 16:55

Updated : 2024-11-21 01:54


NVD link : CVE-2013-3929

Mitre link : CVE-2013-3929

CVE.ORG link : CVE-2013-3929


JSON object : View

Products Affected

cmsmadesimple

  • cms_made_simple
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')