PT-2022-24049 · Pyrocms · Pyrocms

Bruno Barreirinhas

·

Published

2022-11-25

·

Updated

2025-04-25

·

CVE-2022-37721

CVSS v3.1

9.0

Critical

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PyroCMS version 3.9
Description The issue allows a low-privileged user, such as an author, to inject crafted HTML and JavaScript payload in a blog post, leading to full admin account takeover or privilege escalation. This is a stored Cross Site Scripting (XSS) issue.
Recommendations For PyroCMS version 3.9, consider restricting the ability of low-privileged users to inject HTML and JavaScript code in blog posts until a patch is available. As a temporary workaround, disabling the blog post feature for low-privileged users may help minimize the risk of exploitation.

Fix

LPE

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-37721
GHSA-CM7F-HF2G-GHRP

Affected Products

Pyrocms