CVE-2022-28599: XSS
A stored cross-site scripting (XSS) vulnerability exists in FUEL-CMS 1.5.1 that allows an authenticated user to upload a malicious .pdf file which acts as a stored XSS payload. If this stored XSS payload is triggered by an administrator it will trigger a XSS attack.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-28599?
CVE-2022-28599 is a stored cross-site scripting (XSS) vulnerability in FUEL-CMS 1.5.1.
How does the CVE-2022-28599 vulnerability impact FUEL-CMS 1.5.1?
The vulnerability allows an authenticated user to upload a malicious .pdf file that acts as a stored XSS payload, which can be triggered by an administrator to perform a XSS attack.
What is the severity of CVE-2022-28599?
The severity of CVE-2022-28599 is medium, with a CVSS score of 5.4.
How can an authenticated user exploit CVE-2022-28599?
An authenticated user can exploit CVE-2022-28599 by uploading a specially crafted .pdf file containing malicious code.
Is there a fix available for CVE-2022-28599 in FUEL-CMS 1.5.1?
Yes, it is recommended to update FUEL-CMS to a version that includes the fix for CVE-2022-28599.