First published: Tue May 03 2022(Updated: )
A stored cross-site scripting (XSS) vulnerability exists in FUEL-CMS 1.5.1 that allows an authenticated user to upload a malicious .pdf file which acts as a stored XSS payload. If this stored XSS payload is triggered by an administrator it will trigger a XSS attack.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TheDayLightStudio Fuel CMS | =1.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-28599 is a stored cross-site scripting (XSS) vulnerability in FUEL-CMS 1.5.1.
The vulnerability allows an authenticated user to upload a malicious .pdf file that acts as a stored XSS payload, which can be triggered by an administrator to perform a XSS attack.
The severity of CVE-2022-28599 is medium, with a CVSS score of 5.4.
An authenticated user can exploit CVE-2022-28599 by uploading a specially crafted .pdf file containing malicious code.
Yes, it is recommended to update FUEL-CMS to a version that includes the fix for CVE-2022-28599.