PT-2022-25161 · Feehicms · Feehicms

Curta1N-7Op

·

Published

2022-12-15

·

Updated

2022-12-19

·

CVE-2022-40002

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions FeehiCMS version 2.1.1
Description The issue allows remote attackers to run arbitrary code via the callback parameter to the "/cms/notify" API endpoint. This enables attackers to execute malicious scripts on the victim's browser, potentially leading to unauthorized actions or data theft.
Recommendations For FeehiCMS version 2.1.1, as a temporary workaround, consider restricting access to the "/cms/notify" API endpoint or disabling the use of the callback parameter until a patch is available.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-40002
GHSA-6VH6-72G6-XQX2

Affected Products

Feehicms