CVE-2019-10017

Publication date

2019-03-24 21:31:47

Family

mitre

State

PUBLISHED

Description

CMS Made Simple 2.2.10 has XSS via the moduleinterface.php Name field, which is reachable via an "Add a new Profile" action to the File Picker.