CVE-2020-23839
medium · 6.1A Reflected Cross-Site Scripting (XSS) vulnerability in GetSimple CMS v3.3.16, in the admin/index.php login portal webpage, allows remote attackers to execute JavaScript code in the client's browser and harvest login credentials after a client clicks a link, enters credentials, and submits the login form.
6.1
CVSS
10.5%
EPSS (exploit prob.)
96th
EPSS percentile
2020-09-01
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weaknesses
CWE-79
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| get-simple | getsimple_cms | 3.3.16 |
Check a specific version with /api/v1/cve/match.
References
- http://packetstormsecurity.com/files/162016/GetSimple-CMS-3.3.16-Cross-Site-Scripting-Shell-Upload.html
- https://github.com/GetSimpleCMS/GetSimpleCMS/issues/1330
- https://github.com/boku7/CVE-2020-23839
- https://www.exploit-db.com/exploits/49726
- http://packetstormsecurity.com/files/162016/GetSimple-CMS-3.3.16-Cross-Site-Scripting-Shell-Upload.html
- https://github.com/GetSimpleCMS/GetSimpleCMS/issues/1330
- https://github.com/boku7/CVE-2020-23839
- https://www.exploit-db.com/exploits/49726
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2020-23839