CVE-2022-1536: automad Dashboard cross site scripting
A vulnerability has been found in automad up to 1.10.9 and classified as problematic. This vulnerability affects the Dashboard. The manipulation of the argument title with the input Home</title><script>alert("home")</script><title> leads to a cross site scripting. The attack can be initiated remotely but requires an authentication. The exploit details have disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-1536?
CVE-2022-1536 is classified as problematic due to its potential for cross-site scripting.
How do I fix CVE-2022-1536?
To fix CVE-2022-1536, upgrade Automad to a version higher than 1.10.9 that addresses this vulnerability.
What impact does CVE-2022-1536 have on affected systems?
CVE-2022-1536 allows an attacker to inject malicious scripts into the Dashboard, compromising user data and session information.
Which versions of Automad are affected by CVE-2022-1536?
CVE-2022-1536 affects Automad versions up to and including 1.10.9.
Is the CVE-2022-1536 vulnerability easy to exploit?
The cross-site scripting vulnerability in CVE-2022-1536 may be easily exploited by sending crafted payloads to the affected Dashboard.