PT-2022-19097 · Fuel Cms · Fuel Cms
Gidunparo
·
Published
2022-05-03
·
Updated
2022-05-10
·
CVE-2022-28599
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
FUEL-CMS version 1.5.1
Description
A stored cross-site scripting (XSS) issue exists that allows an authenticated user to upload a malicious .pdf file, which acts as a stored XSS payload. If this payload is triggered by an administrator, it will trigger an XSS attack.
Recommendations
For FUEL-CMS version 1.5.1, consider restricting the upload of .pdf files or implementing validation to prevent malicious files from being uploaded until a patch is available. As a temporary workaround, limit administrator access to areas where the stored XSS payload could be triggered.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fuel Cms