search menu icon-carat-right cmu-wordmark

CERT Coordination Center

CMS Made Simple contains multiple cross-site scripting vulnerabilities

Vulnerability Note VU#526062

Original Release Date: 2014-02-28 | Last Revised: 2014-02-28

Overview

CMS Made Simple contains multiple cross-site scripting vulnerabilities

Description

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') - CVE-2014-0334

The files:
cmsmadesimple/admin/addgroup.php on line 107 contains a post-authentication reflected XSS vulnerability in the group parameter.
cmsmadesimple/admin/addhtmlblob.php on line 165 contains a post-authentication reflected XSS vulnerability in the htmlblob parameter.
cmsmadesimple/admin/addbookmark.php on lines 92 and 96 contains a post-authentication reflected XSS vulnerability in the title and url parameters.
cmsmadesimple/admin/copystylesheet.php on line 117 contains a post-authentication reflected XSS vulnerability in the stylesheet_name parameter.
cmsmadesimple/admin/copytemplate.php on line 160 contains a post-authentication reflected XSS vulnerability in the template_name parameter.
cmsmadesimple/admin/editbookmark.php on lines 117 and 121 contains a post-authentication reflected XSS vulnerability in the title and url parameters.
cmsmadesimple/admin/listtemplates.php on line 188 contains a post-authentication persistent XSS vulnerability in the template parameter.
cmsmadesimple/admin/listcss.php on line 172 contains a post-authentication persistent XSS vulnerability in the css_name parameter.

Impact

A remote attacker that is able to trick a logged in administrative user in to visiting a specially crafted URL may be able to conduct a cross-site scripting attack. This attack may result in information leakage, privilege escalation, and/or denial of service.

Solution

We are currently unaware of a practical solution to this problem.

Vendor Information

526062
 

CMS Made Simple Affected

Notified:  January 20, 2014 Updated: February 27, 2014

Status

Affected

Vendor Statement

We have not received a statement from the vendor.

Vendor Information

We are not aware of further vendor information regarding this vulnerability.


CVSS Metrics

Group Score Vector
Base 4.9 AV:N/AC:M/Au:S/C:P/I:P/A:N
Temporal 3.7 E:U/RL:U/RC:UC
Environmental 0.9 CDP:N/TD:L/CR:ND/IR:ND/AR:ND

References

Acknowledgements

Thanks to Pedro Ribeiro of Agile Information Security for reporting this vulnerability.

This document was written by Chris King.

Other Information

CVE IDs: CVE-2014-0334
Date Public: 2014-02-28
Date First Published: 2014-02-28
Date Last Updated: 2014-02-28 15:02 UTC
Document Revision: 21

Sponsored by CISA.