Medium severity6.1NVD Advisory· Published Dec 25, 2018· Updated Jun 17, 2026
CVE-2018-20464
CVE-2018-20464
Description
There is a reflected XSS vulnerability in the CMS Made Simple 2.2.8 admin/myaccount.php. This vulnerability is triggered upon an attempt to modify a user's mailbox with the wrong format. The response contains the user's previously entered email address.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3= 2.2.8+ 1 more
- (no CPE)range: = 2.2.8
- cpe:2.3:a:cmsmadesimple:cms_made_simple:2.2.8:*:*:*:*:*:*:*
- Range: =2.2.8
Patches
Vulnerability mechanics
News mentions
0No linked articles in our index yet.