Skip to content

CVE-2014-1603

Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS 3.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) param parameter to admin/load.php or (2) user, (3) email, or (4) name parameter in a Save Settings action to admin/settings.php.

Ver en NVD

Severidad

N/A

EPSS

Probabilidad de explotación (próx. 30 días): 0.0285 (2.9%)
Percentil: 86.3%
EPSS: 2026-05-06

Afecta

get-simple:getsimple_cms

Descripción técnica

Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS 3.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) param parameter to admin/load.php or (2) user, (3) email, or (4) name parameter in a Save Settings action to admin/settings.php.

Publicada: 14/5/2014, 19:55:10
Última modificación: 6/5/2026, 22:30:45

Referencias

InicioEventosBlogRecursosEquipo