PT-2023-12846 · Jsuites · Jsuites

Ameen Basha M K

·

Publicado

2023-01-31

·

Atualizado

2025-03-27

·

CVE-2022-25979

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions jsuites versions prior to 5.0.1
Description The issue is related to Cross-site Scripting (XSS) due to improper user-input sanitization in the Editor() function. This allows for potential malicious script execution.
Recommendations For versions prior to 5.0.1, update to version 5.0.1 or later to resolve the issue. As a temporary workaround, consider disabling the Editor() function until a patch is available. Restrict access to user-input fields that utilize the Editor() function to minimize the risk of exploitation.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2022-25979
GHSA-R4HG-4CPQ-Q57C

Produtos afetados

Jsuites