PT-2022-27355 · Webtareas · Webtareas

Anhdq201

·

Published

2022-12-02

·

Updated

2022-12-06

·

CVE-2022-44955

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions webtareas version 2.4p5
Description The issue allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Messages field in the Chat function. This enables the execution of malicious code, potentially leading to unauthorized actions on the affected system.
Recommendations For webtareas version 2.4p5, consider disabling the Chat function until a patch is available to prevent exploitation of the cross-site scripting vulnerability. Restrict access to the Messages field to minimize the risk of malicious payload injection.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-44955

Affected Products

Webtareas