PT-2022-23367 · Amasty+1 · Amasty Blog Pro+1
Marcin Wägåowski
·
Published
2022-11-29
·
Updated
2022-12-02
·
CVE-2022-36433
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Amasty Blog Pro version 2.10.3
Description
The blog-post creation functionality in the Amasty Blog Pro plugin for Magento 2 allows injection of JavaScript code in the
short content and full content fields, leading to XSS attacks against admin panel users via "posts/preview" or "posts/save" endpoints.Recommendations
For Amasty Blog Pro version 2.10.3, consider disabling the blog-post creation functionality until a patch is available to prevent XSS attacks. Restrict access to the "posts/preview" and "posts/save" endpoints to minimize the risk of exploitation. Avoid using the
short content and full content fields in the affected plugin until the issue is resolved.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Amasty Blog Pro
Magento 2