A vulnerability identified as problematic has been detected in CMS Made Simple 2.2.15. This impacts an unknown function of the component SVG File Handler. The manipulation leads to cross site scripting. This vulnerability is listed as CVE-2020-37238. The attack may be initiated remotely. In addition, an exploit is available. Weiterlesen
Intelligence View
⚡ tsecurity.de Intelligence
CVE-2020-37238 | CMS Made Simple 2.2.15 SVG File cross site scripting (Exploit 49199)
A vulnerability identified as problematic has been detected in CMS Made Simple 2.2.15. This impacts an unknown function of the component SVG File Handler. The manipulation leads to cross site scripting. This vulnerability is listed as…
Reagiere als Erste:r — dein Feedback zählt!
2. Cyber Threat Intelligence & Forensik
IoC Intelligence (1 Indikatoren)
CVE-2020-37238
Exploit & Remediation Lifecycle Timeline
CVE-2020-37238Entdeckung & Meldung
Schwachstelle identifiziert & registriert
Sicherheits-Advisory
Offizielle Warnung & CVE-Zuweisung
Exploit / PoC
Öffentlicher Nachweis/Code verfügbar (Exploit-DB/EUVD)
In-the-Wild Ausnutzung
Keine Massenausnutzung gemeldet
Patch & Schutzmaßnahmen
Noch kein offizieller Patch dokumentiert
Exploit Weaponization & Public PoC Radar
ELEVATED · Index 15/100Exploit-DB
Kein EDB-EintragInteraktion
Interaktion nötigAuthentifizierung
Erforderlich3. Compliance, SLA & Vendor Adherence
CISA-SSVC-Triage (vulnrichment)CVE-2020-37238
Exploitation: poc (PoC verfügbar)Automatable: no (Nicht automatisierbar)Technical Impact: partial (Teilweise)
Quelle: CISA-ADP vulnrichment · Stand 2026-05-18T17:05:59.354644Z · CISA Coordinator
Advisory Radar
Workaround & Virtual-Patching empfohlen
Hersteller-Sicherheitsmeldungen & Patch-Status
Handlungsempfehlung für Administratoren
Öffentliche PoCs existieren. Isolieren Sie das System oder wenden Sie Micro-Segmentierungsregeln an, bis offizielle Patches vorliegen.
Referenzen aus der Primärquelle („Verifiziert" nur bei Hersteller-Domäne):
-
Web Referencewww.cmsmadesimple.org
-
Web Referencewww.cmsmadesimple.org
2 öffentliche Exploit-Referenz(en) detektiert (Exploit Database (EDB)).
PoC einsehen