PT-2022-27848 · Unknown+4 · Net::Xwhois+4

Carnil

·

Published

2022-12-04

·

Updated

2025-04-24

·

CVE-2022-46391

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions AWStats versions 7.x through 7.8
Description The issue allows for XSS in the hostinfo plugin due to printing a response from Net::XWhois without proper checks.
Recommendations For versions 7.x through 7.8, consider disabling the hostinfo plugin until a patch is available to prevent potential XSS attacks. As a temporary workaround, restrict the use of the Net::XWhois response in the hostinfo plugin to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

ALT-PU-2023-1396
ALT-PU-2024-13582
ALT-PU-2024-13745
CVE-2022-46391
DLA-3225-1
MGASA-2022-0461
USN-5899-1

Affected Products

Alt Linux
Awstats
Linuxmint
Net::Xwhois
Ubuntu