PT-2022-17385 · Unioncms · Unioncms
Lhackl-007
·
Published
2022-06-21
·
Updated
2022-06-28
·
CVE-2022-25585
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Unioncms version 1.0.13
Description
The issue is related to a stored cross-site scripting (XSS) vulnerability. This vulnerability occurs via the Default settings, allowing potential attackers to inject malicious scripts into the application.
Recommendations
For Unioncms version 1.0.13, update the software to a version that fixes the stored XSS vulnerability, or as a temporary workaround, consider restricting access to the Default settings to minimize the risk of exploitation.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Unioncms