CVE-2022-25410: XSS
Published Feb 28, 2022
·Updated
Maxsite CMS v180 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the parameter ffiledescription at /admin/files.
Affected Software
1 affected component
Max-3000 Maxsite Cms=108
Remediation
Patch Available
Event History
Feb 28, 2022
CVE Published
via MITRE·10:55 PM
Data Sourced
via MITRE·10:55 PM
Description
Frequently Asked Questions
1
What is CVE-2022-25410?
CVE-2022-25410 is a stored cross-site scripting (XSS) vulnerability in Maxsite CMS v180.
2
How does CVE-2022-25410 affect Maxsite CMS?
CVE-2022-25410 affects Maxsite CMS v180 through the parameter f_file_description at /admin/files.
3
What is the severity of CVE-2022-25410?
The severity of CVE-2022-25410 is medium with a CVSS score of 5.4.
4
What is the CWE classification of CVE-2022-25410?
CVE-2022-25410 is classified as CWE-79, which is a Cross-Site Scripting (XSS) vulnerability.
5
Is there a fix available for CVE-2022-25410?
At the moment, there is no known fix available for CVE-2022-25410. It is recommended to update to the latest version of Maxsite CMS when a fix becomes available.