PT-2022-22911 · Fork Cms · Fork Cms

Published

2022-08-12

·

Updated

2022-08-15

·

CVE-2022-35585

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions ForkCMS versions prior to 5.11.0
Description A stored cross-site scripting (XSS) issue allows remote attackers to inject JavaScript via the start date Parameter. This issue was patched in version 5.11.0.
Recommendations For ForkCMS versions prior to 5.11.0, update to version 5.11.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the start date Parameter until a patch is applied.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-35585
GHSA-9HMC-87H4-W869

Affected Products

Fork Cms