Description
CMSimple 5.4 contains a cross-site scripting vulnerability that allows attackers to bypass input filtering by using HTML to Unicode encoding. Attackers can inject malicious scripts by encoding payloads like ')-alert(1)// and execute arbitrary JavaScript when victims interact with delete buttons.
Problem types
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
Credits
heinjame
References
www.exploit-db.com/exploits/50612 (ExploitDB-50612)
www.cmsimple.org/en/ (CMSimple Official Homepage)
www.vulncheck.com/...ite-scripting-via-html-unicode-encoding (VulnCheck Advisory: CMSimple 5.4 Cross-Site Scripting via HTML Unicode Encoding)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.