PT-2022-17937 · Maccms · Maccms

Kpa1On

·

Published

2022-03-25

·

Updated

2026-01-26

·

CVE-2022-26573

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Maccms version 10
Description The issue is related to multiple reflected cross-site scripting (XSS) vulnerabilities. These vulnerabilities are found in the /admin.php/admin/art/data.html endpoint via the select and input parameters.
Recommendations For Maccms version 10, consider disabling access to the /admin.php/admin/art/data.html endpoint until a fix is available. As a temporary workaround, restrict the use of the select and input parameters in this endpoint to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-26573

Affected Products

Maccms