PT-2022-27723 · Aerocms · Aerocms

Published

2022-12-13

·

Updated

2022-12-15

·

CVE-2022-46058

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions AeroCMS version 0.0.1
Description The issue allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Comments text field in the add post.php file. This enables the execution of malicious code, potentially leading to security breaches.
Recommendations For AeroCMS version 0.0.1, as a temporary workaround, consider restricting access to the add post.php file or disabling the Comments text field until a patch is available. Avoid using the Comments field in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-46058

Affected Products

Aerocms