PT-2022-20360 · Fudforum · Fudforum
Sonnguyen3496
·
Published
2022-06-06
·
Updated
2022-06-13
·
CVE-2022-30863
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
FUDForum version 3.1.2
Description
The issue is related to Cross Site Scripting (XSS) via the
page title param in the Page Manager within the Admin Control Panel.Recommendations
For FUDForum version 3.1.2, consider restricting access to the Page Manager in the Admin Control Panel to minimize the risk of exploitation, and avoid using the
page title param until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fudforum