Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Marcin Wägåowski

#43561of 53,633
6.1Total CVSS
Vulnerabilities · 1
PT-2022-23367
6.1
2022-11-29
Amasty · Amasty Blog Pro · CVE-2022-36433
**Name of the Vulnerable Software and Affected Versions** Amasty Blog Pro version 2.10.3 **Description** The blog-post creation functionality in the Amasty Blog Pro plugin for Magento 2 allows injection of JavaScript code in the `short content` and `full content` fields, leading to XSS attacks against admin panel users via "posts/preview" or "posts/save" endpoints. **Recommendations** For Amasty Blog Pro version 2.10.3, consider disabling the blog-post creation functionality until a patch is available to prevent XSS attacks. Restrict access to the "posts/preview" and "posts/save" endpoints to minimize the risk of exploitation. Avoid using the `short content` and `full content` fields in the affected plugin until the issue is resolved.