PT-2022-27141 · Unknown · Rathena Fluxcp

CVE-2022-4421

·

Published

2022-12-12

·

Updated

2022-12-15

CVSS v3.1

3.5

Low

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions rAthena FluxCP (affected versions not specified)
Description A vulnerability was found in the Service Desk Image URL Handler component of rAthena FluxCP, affecting an unknown function of the file themes/default/servicedesk/view.php. The manipulation of the sslink argument leads to cross-site scripting. It is possible to launch the attack remotely.
Recommendations To fix this issue, it is recommended to apply a patch. The name of the patch is 8a39b2b2bf28353b3503ff1421862393db15aa7e. As a temporary workaround, consider restricting access to the view.php file in the themes/default/servicedesk directory until a patch is available. Additionally, avoid using the sslink argument in the affected API endpoint until the issue is resolved.

Exploit

Fix

Improper Neutralization

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-4421

Affected Products

Rathena Fluxcp