Total vulnerabilities in the database
In admin\addgroup.php in CMS Made Simple 2.1.6, when adding a user group, there is no XSS filtering, resulting in storage-type XSS generation, via the description parameter in an addgroup action.
Software | From | Fixed in |
---|---|---|
cmsmadesimple / cms_made_simple | 2.1.6 | 2.1.6.x |