peter bassill · operator
$ cve CVE-2016-2784 JSON

CVE-2016-2784 EXPLOIT

4.7
MEDIUM · CVSS 3.0 · EPSS 2.5% (pctl 84)

Patch early

A public exploit exists.

Description

CMS Made Simple 2.x before 2.1.3 and 1.x before 1.12.2, when Smarty Cache is activated, allow remote attackers to conduct cache poisoning attacks, modify links, and conduct cross-site scripting (XSS) attacks via a crafted HTTP Host header in a request.

Scoring

CVSS4.7 (MEDIUM, v3.0)
VectorCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS2.45% — more likely to be exploited than 84% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2016-05-26
Last modified2026-06-17

Affected (1)

VendorProduct
cmsmadesimplecms made simple

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD