PT-2026-2413 · Unknown · Ametys Cms

Vulnerability-Lab

·

Published

2026-01-13

·

Updated

2026-02-02

·

CVE-2022-50937

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Ametys CMS version 4.4.1
Description Ametys CMS version 4.4.1 has a persistent cross-site scripting issue in the link directory’s input fields for external links. An attacker can inject malicious script code into the link text and descriptions, leading to persistent attacks that can compromise user sessions and manipulate application modules. The issue allows for the execution of malicious scripts when users access the affected links.
Recommendations Update Ametys CMS to a version that addresses this issue. As a temporary workaround, sanitize all input data for external links in the link directory to prevent the injection of malicious scripts.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-50937

Affected Products

Ametys Cms