Medium severity6.1NVD Advisory· Published Sep 25, 2023· Updated Jun 17, 2026
CVE-2023-43339
CVE-2023-43339
Description
Cross-Site Scripting (XSS) vulnerability in cmsmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted payload injected into the Database Name, DataBase User or Database Port components.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:cmsmadesimple:cms_made_simple:2.2.18:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:cmsmadesimple:cms_made_simple:2.2.18:*:*:*:*:*:*:*
- (no CPE)
- (no CPE)range: =2.2.18
Patches
Vulnerability mechanics
References
3- github.com/sromanhu/CVE-2023-43339-CMSmadesimple-Reflected-XSS---Installation/blob/main/README.mdnvdExploitThird Party Advisory
- github.com/sromanhu/Cmsmadesimple-CMS-Stored-XSS/blob/main/README.mdnvdExploitThird Party Advisory
- www.cmsmadesimple.orgnvdProduct
News mentions
0No linked articles in our index yet.