PT-2022-24975 · Unknown · Sanluan Publiccms

·

CVE-2022-3950

·

Published

2022-11-11

·

Updated

2023-12-28

CVSS v3.1

3.5

Low

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions sanluan PublicCMS (affected versions not specified)
Description A vulnerability was found in sanluan PublicCMS, affecting the function initLink of the file dwz.min.js of the component Tab Handler. The manipulation leads to cross-site scripting. It is possible to launch the attack remotely.
Recommendations To fix this issue, it is recommended to apply a patch with the name a972dc9b1c94aea2d84478bf26283904c21e4ca2. As a temporary workaround, consider disabling the initLink function until a patch is available. Restrict access to the dwz.min.js file to minimize the risk of exploitation.

Exploit

Fix

Improper Neutralization

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-3950

Affected Products

Sanluan Publiccms