📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global phishing Cross-sector HIGH 4h Global data_breach Energy CRITICAL 6h Global phishing Government/Multi-sector HIGH 6h Global apt Education CRITICAL 8h Global vulnerability Enterprise Software / ERP Systems CRITICAL 9h Global vulnerability IT Infrastructure CRITICAL 10h Global vulnerability Technology and Software Development HIGH 11h Global vulnerability Enterprise IT and Government CRITICAL 11h Global ransomware Multiple Sectors / Enterprise CRITICAL 12h Global general Technology and Legal MEDIUM 13h Global phishing Cross-sector HIGH 4h Global data_breach Energy CRITICAL 6h Global phishing Government/Multi-sector HIGH 6h Global apt Education CRITICAL 8h Global vulnerability Enterprise Software / ERP Systems CRITICAL 9h Global vulnerability IT Infrastructure CRITICAL 10h Global vulnerability Technology and Software Development HIGH 11h Global vulnerability Enterprise IT and Government CRITICAL 11h Global ransomware Multiple Sectors / Enterprise CRITICAL 12h Global general Technology and Legal MEDIUM 13h Global phishing Cross-sector HIGH 4h Global data_breach Energy CRITICAL 6h Global phishing Government/Multi-sector HIGH 6h Global apt Education CRITICAL 8h Global vulnerability Enterprise Software / ERP Systems CRITICAL 9h Global vulnerability IT Infrastructure CRITICAL 10h Global vulnerability Technology and Software Development HIGH 11h Global vulnerability Enterprise IT and Government CRITICAL 11h Global ransomware Multiple Sectors / Enterprise CRITICAL 12h Global general Technology and Legal MEDIUM 13h
Vulnerabilities

CVE-2020-37238

Medium
CWE-79 — Weakness Type
Published: May 16, 2026  ·  Modified: May 19, 2026  ·  Source: NVD
CVSS v3
6.4
🔗 NVD Official
📄 Description (English)

CMS Made Simple 2.2.15 contains a stored cross-site scripting vulnerability that allows authenticated users with Content Manager access to inject malicious scripts through SVG file uploads. Attackers can upload SVG files containing embedded JavaScript to the file manager, which executes when other authenticated users access the uploaded file, enabling cookie theft and session hijacking.

🤖 AI Executive Summary

CMS Made Simple 2.2.15 contains a stored XSS vulnerability in SVG file upload functionality that allows authenticated Content Managers to inject malicious scripts. When other authenticated users access uploaded SVG files, embedded JavaScript executes, enabling session hijacking and credential theft. This vulnerability poses a significant insider threat risk, particularly in organizations using CMS Made Simple for content management and collaboration.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: May 16, 2026 22:17
🇸🇦 Saudi Arabia Impact Assessment
Saudi government agencies, municipalities, and educational institutions using CMS Made Simple for content management face elevated risk. The vulnerability particularly impacts organizations in the public sector (NCA oversight), healthcare institutions managing patient information portals, and telecommunications companies using CMS for customer-facing content. The stored nature of the XSS means compromised sessions could provide persistent access to sensitive government or institutional data. Risk is amplified in environments with privileged Content Manager accounts managing critical information.
🏢 Affected Saudi Sectors
Government Education Healthcare Telecommunications Media and Publishing Local Authorities
⚖️ Saudi Risk Score (AI)
6.8
/ 10.0
🔧 Remediation Steps (English)
Immediate Actions:
1. Audit all SVG files currently uploaded in CMS Made Simple 2.2.15 instances for suspicious content or embedded scripts
2. Review Content Manager account access logs for unauthorized file uploads in the past 90 days
3. Implement file upload restrictions: disable SVG uploads or restrict to trusted administrators only
4. Enforce Content Security Policy (CSP) headers to prevent inline script execution

Patching Guidance:
5. Upgrade to CMS Made Simple version 2.2.16 or later when available (currently no patch released - monitor vendor advisories)
6. If upgrade unavailable, implement input validation to sanitize SVG files before storage

Compensating Controls:
7. Deploy Web Application Firewall (WAF) rules to detect and block SVG files containing script tags
8. Implement strict file type validation on server-side (verify MIME type and file signature)
9. Store uploaded files outside web root or serve with Content-Disposition: attachment header
10. Enable session timeout policies and implement re-authentication for sensitive operations
11. Deploy endpoint detection and response (EDR) to monitor for suspicious session activity
12. Conduct security awareness training for Content Manager users on file upload risks

Detection Rules:
13. Monitor for SVG uploads containing <script>, javascript:, or event handlers (onload, onerror, etc.)
14. Alert on multiple authenticated users accessing same SVG file within short timeframe
15. Track session token usage anomalies post-SVG file access
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. تدقيق جميع ملفات SVG المحملة حاليًا في مثيلات CMS Made Simple 2.2.15 للبحث عن محتوى مريب أو نصوص برمجية مضمنة
2. مراجعة سجلات الوصول لحسابات مدير المحتوى للبحث عن تحميلات ملفات غير مصرح بها في آخر 90 يومًا
3. تنفيذ قيود تحميل الملفات: تعطيل تحميل SVG أو تقييده على المسؤولين الموثوقين فقط
4. فرض رؤوس سياسة أمان المحتوى (CSP) لمنع تنفيذ النصوص البرمجية المضمنة

إرشادات التصحيح:
5. الترقية إلى CMS Made Simple الإصدار 2.2.16 أو أحدث عند توفره (لا يوجد تصحيح حاليًا - راقب إشعارات البائع)
6. إذا لم تكن الترقية متاحة، قم بتنفيذ التحقق من الإدخال لتنظيف ملفات SVG قبل التخزين

الضوابط البديلة:
7. نشر قواعد جدار حماية تطبيقات الويب (WAF) للكشف عن ملفات SVG التي تحتوي على علامات نصية وحظرها
8. تنفيذ التحقق الصارم من نوع الملف على جانب الخادم (التحقق من نوع MIME وتوقيع الملف)
9. تخزين الملفات المحملة خارج جذر الويب أو تقديمها برأس Content-Disposition: attachment
10. تفعيل سياسات انتهاء صلاحية الجلسة وتنفيذ إعادة المصادقة للعمليات الحساسة
11. نشر كشف نقاط النهاية والاستجابة (EDR) لمراقبة نشاط الجلسة المريب
12. إجراء تدريب الوعي الأمني لمستخدمي مدير المحتوى حول مخاطر تحميل الملفات

قواعد الكشف:
13. مراقبة تحميلات SVG التي تحتوي على <script> أو javascript: أو معالجات الأحداث (onload, onerror, إلخ)
14. التنبيه على وصول عدة مستخدمين مصرح لهم إلى نفس ملف SVG في إطار زمني قصير
15. تتبع شذوذ استخدام رمز الجلسة بعد الوصول إلى ملف SVG
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
A.14.2.1 - Secure development policy and procedures A.14.2.5 - Secure development environment A.12.6.1 - Management of technical vulnerabilities A.12.2.1 - Monitoring of system use
🔵 SAMA CSF
ID.SC-4 - Supply chain risk management PR.AC-1 - Access control policy and procedures PR.AC-3 - Access enforcement DE.CM-1 - The organization monitors systems and networks
🟡 ISO 27001:2022
A.6.1.1 - Information security policies A.12.2.1 - User access management A.12.4.1 - Event logging A.14.2.1 - Secure development policy A.14.2.5 - Secure development environment
🟣 PCI DSS v4.0.1
6.5.1 - Injection flaws prevention 6.5.7 - Cross-site scripting prevention 10.2.1 - User access logging
📊 CVSS Score
6.4
/ 10.0 — Medium
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredL — Low / Local
User InteractionN — None / Network
ScopeC — Changed
ConfidentialityL — Low / Local
IntegrityL — Low / Local
AvailabilityN — None / Network
📋 Quick Facts
Severity Medium
CVSS Score6.4
CWECWE-79
EPSS0.03%
Exploit No
Patch ✗ No
Published 2026-05-16
Source Feed nvd
🇸🇦 Saudi Risk Score
6.8
/ 10.0 — Saudi Risk
Priority: HIGH
🏷️ Tags
CWE-79
Share this CVE
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.