PT-2022-22021 · Feehicms · Feehicms

Shivamking05675

·

Published

2022-07-27

·

Updated

2022-10-26

·

CVE-2022-34140

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Feehi CMS version 2.1.1
Description A stored cross-site scripting (XSS) issue exists in the /index.php?r=site%2Fsignup endpoint of Feehi CMS, allowing attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username field.
Recommendations For Feehi CMS version 2.1.1, update to a version that fixes this issue, as the current version allows for the execution of arbitrary web scripts or HTML. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-34140
GHSA-25Q6-M425-9FQR

Affected Products

Feehicms