Description
Simple CMS 2.1 contains a non-persistent cross-site scripting vulnerability in the preview.php file's id parameter. Attackers can inject malicious script code through a GET request to execute arbitrary scripts and potentially hijack user sessions or perform phishing attacks.
Problem types
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
2.1
Credits
Vulnerability-Lab [Research Team]
References
www.vulnerability-lab.com/get_content.php?id=2301 (Vulnerability Lab Advisory)
simplephpscripts.com/simple-cms-php (Product Homepage)
www.vulncheck.com/...ss-site-scripting-via-preview-parameter (VulnCheck Advisory: Simple CMS 2.1 Non-Persistent Cross-Site Scripting via Preview Parameter)