CVE-2022-27884: XSS
Published Mar 25, 2022
·Updated
Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/plog/index.html via the wd parameter.
Affected Software
11 affected components
maccms Maccms=10.0-2021.1000.1081
maccms Maccms=10.0-2022.1000.1099
maccms Maccms=10.0-2022.1000.3001
maccms Maccms=10.0-2022.1000.3002
maccms Maccms=10.0-2022.1000.3004
maccms Maccms=10.0-2022.1000.3005
maccms Maccms=10.0-2022.1000.3025
maccms Maccms=10.0-2022.1000.3026
maccms Maccms=10.0-2022.1000.3027
maccms Maccms=10.0-2022.1000.3028
maccms Maccms=10.0-2022.1000.3029
Event History
Mar 25, 2022
CVE Published
via MITRE·06:50 PM
Data Sourced
via MITRE·06:50 PM
Description
Frequently Asked Questions
1
What is CVE-2022-27884?
CVE-2022-27884 is a reflected cross-site scripting (XSS) vulnerability in Maccms v10.
2
How severe is CVE-2022-27884?
CVE-2022-27884 has a severity rating of 6.1 (medium).
3
How does CVE-2022-27884 affect Maccms v10?
CVE-2022-27884 affects Maccms v10 versions 10.0-2021.1000.1081 through 10.0-2022.1000.3029.
4
What is the CWE ID for CVE-2022-27884?
The CWE ID for CVE-2022-27884 is CWE-79.
5
Is there a fix available for CVE-2022-27884?
There is currently no known fix for CVE-2022-27884. It is recommended to follow the suggested mitigation steps provided by the software vendor or developer.