PT-2026-2413 · Unknown · Ametys Cms
Vulnerability-Lab
·
Published
2026-01-13
·
Updated
2026-02-02
·
CVE-2022-50937
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Ametys CMS version 4.4.1
Description
Ametys CMS version 4.4.1 has a persistent cross-site scripting issue in the link directory’s input fields for external links. An attacker can inject malicious script code into the link text and descriptions, leading to persistent attacks that can compromise user sessions and manipulate application modules. The issue allows for the execution of malicious scripts when users access the affected links.
Recommendations
Update Ametys CMS to a version that addresses this issue. As a temporary workaround, sanitize all input data for external links in the link directory to prevent the injection of malicious scripts.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ametys Cms