PT-2022-12272 · Taocms · Taocms
Liangyueliangyue
·
Published
2022-02-10
·
Updated
2022-02-16
·
CVE-2021-44969
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Taocms version 3.0.2
Description
The issue is related to a cross-site scripting (XSS) vulnerability. This vulnerability was found in the Management Column component.
Recommendations
For Taocms version 3.0.2, consider disabling the Management Column component until a patch is available. Restrict access to this component to minimize the risk of exploitation.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Taocms