logo

CVE-2022-4640 net.mingsoft:ms-mcms

Package

Manager: maven
Name: net.mingsoft:ms-mcms
Vulnerable Version: >=0 <=5.2.9

Severity

Level: Medium

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

EPSS: 0.0006 pctl0.18924

Details

Mingsoft MCMS Cross-site Scripting vulnerability A vulnerability has been found in Mingsoft MCMS 5.2.9 and classified as problematic. Affected by this vulnerability is the function save of the component Article Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-216499.

Metadata

Created: 2022-12-22T00:30:36Z
Modified: 2022-12-29T23:36:19Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/12/GHSA-6rvv-h8g7-728w/GHSA-6rvv-h8g7-728w.json
CWE IDs: ["CWE-79"]
Alternative ID: GHSA-6rvv-h8g7-728w
Finding: F425
Auto approve: 1