Cross-site scripting (XSS) vulnerability in admin/template/js/uploadify/uploadify.swf in GetSimple CMS 3.3.13 allows remote attackers to inject arbitrary web script or HTML, as demonstrated by the movieName parameter.
| Software | From | Fixed in |
|---|---|---|
| get-simple / getsimple_cms | 3.3.13 | 3.3.13.x |