PT-2022-20473 · Adminlte · Adminlte

Pj1234678

·

Published

2022-07-07

·

Updated

2022-12-23

·

CVE-2022-31029

CVSS v3.1

5.9

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions AdminLTE (affected versions not specified)
Description The issue allows an attacker to execute scripts by inserting malicious code, such as <script>alert("XSS")</script>, into the "Domain to look for" field and then triggering the execution by hitting enter or clicking on any of the buttons. This requires the attacker to be logged in, which is typically limited to administrators, thus minimizing the risk. There are no known instances of this issue being exploited in real-world attacks.
Recommendations Upgrade to a newer version to resolve the issue. As a temporary workaround, consider restricting access to the "Domain to look for" field to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-31029
GHSA-CFR5-RQM5-9VHP

Affected Products

Adminlte