PT-2022-26997 · Unknown · Sling App Cms

Published

2022-11-02

·

Updated

2022-11-03

·

CVE-2022-43670

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Sling App CMS versions 1.1.0 and prior
Description The issue is related to an improper neutralization of input during web page generation, also known as Cross-site Scripting. This may allow an authenticated remote attacker to perform a reflected cross site scripting (XSS) attack in the taxonomy management feature.
Recommendations For Sling App CMS versions 1.1.0 and prior, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-43670
GHSA-JJ93-4JR5-X45H

Affected Products

Sling App Cms