PT-2022-24975 · Unknown · Sanluan Publiccms
Sanluan
·
Published
2022-11-11
·
Updated
2023-12-28
·
CVE-2022-3950
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
sanluan PublicCMS (affected versions not specified)
Description
A vulnerability was found in sanluan PublicCMS, affecting the function
initLink of the file dwz.min.js of the component Tab Handler. The manipulation leads to cross-site scripting. It is possible to launch the attack remotely.Recommendations
To fix this issue, it is recommended to apply a patch with the name
a972dc9b1c94aea2d84478bf26283904c21e4ca2. As a temporary workaround, consider disabling the initLink function until a patch is available. Restrict access to the dwz.min.js file to minimize the risk of exploitation.Fix
Improper Neutralization
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sanluan Publiccms