First published: Wed Feb 09 2022(Updated: )
Exponent CMS 2.6.0patch2 allows an authenticated admin user to inject persistent JavaScript code inside the "Site/Organization Name","Site Title" and "Site Header" parameters while updating the site settings on "/exponentcms/administration/configure_site"
Credit: help@fluidattacks.com
Affected Software | Affected Version | How to fix |
---|---|---|
Exponentcms Exponent Cms | =2.6.0-patch2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-23047 is considered a critical vulnerability due to the potential for persistent cross-site scripting (XSS) attacks.
To fix CVE-2022-23047, you should upgrade to a patched version of Exponent CMS that addresses this vulnerability.
CVE-2022-23047 affects users of Exponent CMS version 2.6.0-patch2 who have administrative access.
CVE-2022-23047 is a persistent cross-site scripting (XSS) vulnerability.
CVE-2022-23047 can allow attackers to inject malicious JavaScript code, compromising the security of the web application and its users.