PT-2022-25403 · Unknown · Processwire
Filipe Azevedo
+1
·
Published
2022-10-31
·
Updated
2022-11-01
·
CVE-2022-40487
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
ProcessWire version 3.0.200
Description
The issue allows attackers to execute arbitrary web scripts or HTML via injection of a crafted payload, leveraging multiple cross-site scripting (XSS) vulnerabilities. These vulnerabilities are specifically found in the Search Users and Search Pages function.
Recommendations
For version 3.0.200, consider disabling the Search Users and Search Pages functions until a patch is available to prevent exploitation of the XSS vulnerabilities. Restrict access to these functions to minimize the risk of arbitrary web script or HTML execution.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Processwire