PT-2022-20114 · Neos Cms · Neos Cms

Nina Wagner

·

Published

2022-06-02

·

Updated

2024-03-06

·

CVE-2022-30429

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Neos CMS versions 3.3.29 through 8.0.1
Description Multiple cross-site scripting (XSS) vulnerabilities in Neos CMS allow attackers with the editor role or higher to inject arbitrary script or HTML code using the editor function, the deletion of assets, or a workspace title.
Recommendations For versions 3.3.29 through 8.0.1, consider disabling the editor function, asset deletion, and workspace title editing for users with the editor role or higher until a patch is available. Restrict access to the editor function, asset deletion, and workspace title editing to minimize the risk of exploitation. Avoid using the affected features in the editor function, asset deletion, and workspace title editing until the issue is resolved.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BIT-NEOS-2022-30429
CVE-2022-30429
GHSA-7M9H-V68W-PFW3

Affected Products

Neos Cms