PT-2026-2413 · Unknown · Ametys Cms
Vulnerability-Lab
·
Publicado
2026-01-13
·
Atualizado
2026-02-02
·
CVE-2022-50937
CVSS v3.1
6.1
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Ametys CMS version 4.4.1
Description
Ametys CMS version 4.4.1 has a persistent cross-site scripting issue in the link directory’s input fields for external links. An attacker can inject malicious script code into the link text and descriptions, leading to persistent attacks that can compromise user sessions and manipulate application modules. The issue allows for the execution of malicious scripts when users access the affected links.
Recommendations
Update Ametys CMS to a version that addresses this issue. As a temporary workaround, sanitize all input data for external links in the link directory to prevent the injection of malicious scripts.
Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ametys Cms