CVE-2022-33098: XSS
Magnolia CMS v6.2.19 was discovered to contain a cross-site scripting (XSS) vulnerability via the Edit Contact function. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
Other sources
Magnolia CMS v6.2.19 was discovered to contain a cross-site scripting (XSS) vulnerability via the Edit Contact function. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted SVG document, with JavaScript, for a profile picture.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-33098?
CVE-2022-33098 has been rated as a high severity vulnerability due to the potential for attackers to execute arbitrary scripts.
How do I fix CVE-2022-33098?
To fix CVE-2022-33098, you should upgrade Magnolia CMS to version 6.2.20 or later.
What are the implications of CVE-2022-33098?
CVE-2022-33098 can lead to unauthorized access, data theft, and the execution of malicious scripts on affected systems.
Who is affected by CVE-2022-33098?
CVE-2022-33098 affects users of Magnolia CMS version 6.2.19.
What type of vulnerability is CVE-2022-33098?
CVE-2022-33098 is classified as a cross-site scripting (XSS) vulnerability.