PT-2022-23366 · Amasty+1 · Amasty Blog Pro+1

Published

2022-11-17

·

Updated

2022-11-21

·

CVE-2022-36432

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Amasty Blog Pro version 2.10.3
Description The Preview functionality in the Amasty Blog Pro plugin for Magento 2 uses eval unsafely, allowing attackers to perform Cross-site Scripting attacks on admin panel users by manipulating the generated preview application response.
Recommendations For Amasty Blog Pro version 2.10.3, consider disabling the Preview functionality until a patch is available to prevent Cross-site Scripting attacks.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-36432

Affected Products

Amasty Blog Pro
Magento 2