PT-2022-15808 · Unknown · Exponent Cms

Alestorm980

·

Published

2022-02-09

·

Updated

2022-02-17

·

CVE-2022-23049

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Exponent CMS version 2.6.0patch2
Description The issue allows an authenticated user to inject persistent JavaScript code through the User-Agent header when logging in. This code is triggered when an administrator visits the "User Sessions" tab, potentially compromising the administrator's session.
Recommendations For Exponent CMS version 2.6.0patch2, consider disabling access to the "User Sessions" tab until a patch is available to prevent exploitation of the JavaScript injection vulnerability. Restrict the ability for users to inject custom JavaScript code through the User-Agent header to minimize the risk of session compromise.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-23049

Affected Products

Exponent Cms