PT-2022-24992 · Unknown · Nukeviet Cms

Published

2022-11-13

·

Updated

2022-11-18

·

CVE-2022-3975

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions NukeViet CMS versions prior to 4.5
Description A vulnerability has been found in the function filterAttr of the file vendor/vinades/nukeviet/Core/Request.php of the component Data URL Handler. The manipulation of the argument attrSubSet leads to cross-site scripting. The attack may be launched remotely.
Recommendations To address this issue, upgrade to version 4.5. As a temporary workaround, consider restricting access to the filterAttr function until the upgrade is applied. Additionally, avoid using the attrSubSet argument in the affected component until the issue is resolved.

Fix

Improper Neutralization

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-3975
GHSA-X45F-J34V-75XM

Affected Products

Nukeviet Cms