PT-2022-27356 · Webtareas · Webtareas

Anhdq201

·

Published

2022-12-02

·

Updated

2022-12-06

·

CVE-2022-44956

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions webtareas version 2.4p5
Description The issue allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field in the /projects/listprojects.php component. This enables the execution of malicious code, potentially leading to unauthorized actions on the affected system.
Recommendations For webtareas version 2.4p5, consider disabling the /projects/listprojects.php component until a patch is available to prevent exploitation. Restrict access to this component to minimize the risk of arbitrary code execution. Avoid using the Name field in the affected component until the issue is resolved.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-44956

Affected Products

Webtareas