PT-2022-11665 · Unknown · Imprint Cms
Published
2022-12-21
·
Updated
2022-12-27
·
CVE-2021-4270
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Imprint CMS (affected versions not specified)
Description
A vulnerability was found in Imprint CMS, classified as problematic. The issue affects the
SearchForm function of the file ImprintCMS/Models/ViewHelpers.cs. The manipulation of the query argument leads to cross-site scripting. It is possible to launch the attack remotely.Recommendations
To fix this issue, it is recommended to apply a patch. The name of the patch is 6140b140ccd02b5e4e7d6ba013ac1225724487f4. As a temporary workaround, consider disabling the
SearchForm function until a patch is available. Restrict access to the ImprintCMS/Models/ViewHelpers.cs file to minimize the risk of exploitation. Avoid using the query argument in the affected function until the issue is resolved.Fix
XSS
Improper Neutralization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Imprint Cms