CVE-2022-27886: XSS
Published Mar 25, 2022
·Updated
Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/ulog/index.html via the wd parameter.
Affected Software
11 affected components
maccms Maccms=10.0-2021.1000.1081
maccms Maccms=10.0-2022.1000.1099
maccms Maccms=10.0-2022.1000.3001
maccms Maccms=10.0-2022.1000.3002
maccms Maccms=10.0-2022.1000.3004
maccms Maccms=10.0-2022.1000.3005
maccms Maccms=10.0-2022.1000.3025
maccms Maccms=10.0-2022.1000.3026
maccms Maccms=10.0-2022.1000.3027
maccms Maccms=10.0-2022.1000.3028
maccms Maccms=10.0-2022.1000.3029
Event History
Mar 25, 2022
CVE Published
via MITRE·06:50 PM
Data Sourced
via MITRE·06:50 PM
Description
Frequently Asked Questions
1
What is CVE-2022-27886?
CVE-2022-27886 is a reflected cross-site scripting (XSS) vulnerability in Maccms v10.
2
What is the severity of CVE-2022-27886?
The severity of CVE-2022-27886 is medium with a severity value of 6.1.
3
Which software versions are affected by CVE-2022-27886?
Maccms v10 versions 10.0-2021.1000.1081 to 10.0-2022.1000.3029 are affected by CVE-2022-27886.
4
How can I fix CVE-2022-27886?
To fix CVE-2022-27886, apply the latest patches or updates provided by Maccms v10.
5
Where can I find more information about CVE-2022-27886?
You can find more information about CVE-2022-27886 on the GitHub issue page: https://github.com/magicblack/maccms10/issues/840.