PT-2022-15962 · Unknown · Tastyigniter
Eric Getchell
+1
·
Published
2022-02-09
·
Updated
2022-02-11
·
CVE-2022-23378
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
TastyIgniter version 3.2.2
Description
A Cross-Site Scripting (XSS) issue exists. The
items%5B0%5D%5Bpath%5D parameter of a request made to "/admin/allergens/edit/1" is vulnerable.Recommendations
For version 3.2.2, as a temporary workaround, consider restricting access to the "/admin/allergens/edit/1" endpoint until a patch is available. Avoid using the
items%5B0%5D%5Bpath%5D parameter in the affected endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tastyigniter