Medium severity5.4NVD Advisory· Published Sep 28, 2023· Updated Jun 17, 2026
CVE-2023-43872
CVE-2023-43872
Description
A File upload vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to upload a pdf file with hidden Cross Site Scripting (XSS).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:cmsmadesimple:cms_made_simple:2.2.18:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:cmsmadesimple:cms_made_simple:2.2.18:*:*:*:*:*:*:*
- (no CPE)
- (no CPE)range: =2.2.18
Patches
Vulnerability mechanics
News mentions
0No linked articles in our index yet.