PT-2022-2236 · Unknown · Nginx Proxy Manager

L4Rm4Nd

·

Published

2022-03-24

·

Updated

2022-04-11

·

CVE-2022-28379

CVSS v2.0

8.3

High

VectorAV:N/AC:L/Au:M/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Nginx Proxy Manager versions prior to 2.9.17
Description The issue exists due to inadequate protection of the web page structure in the proxy manager. This can be exploited by a remote attacker to impact the confidentiality, integrity, and availability of protected information. The vulnerability allows for XSS during item deletion.
Recommendations For versions prior to 2.9.17, update to version 2.9.17 or later to resolve the issue. As a temporary workaround, consider restricting access to the item deletion functionality until a patch is available.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-02322
CVE-2022-28379

Affected Products

Nginx Proxy Manager