PT-2022-25160 · Feehicms · Feehicms

Curta1N-7

·

Published

2022-12-15

·

Updated

2022-12-19

·

CVE-2022-40001

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions FeehiCMS version 2.1.1
Description The issue allows remote attackers to run arbitrary code via the title field of the create article page. This is a Cross Site Scripting (XSS) issue, which means an attacker can inject malicious scripts into the website, potentially leading to unauthorized access or control.
Recommendations For FeehiCMS version 2.1.1, as a temporary workaround, consider restricting access to the create article page or sanitizing the title field input to prevent code injection. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-40001
GHSA-GQGQ-784Q-V9XP

Affected Products

Feehicms