CVE-2022-34025: XSS
Published Jul 19, 2022
·Updated
Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the post function at /web/api/v1/upload/UploadHandler.php.
Affected Software
1 affected component
VestaCP Vesta Control Panel=1.0.0-5
Event History
Jul 19, 2022
CVE Published
via MITRE·06:20 PM
Data Sourced
via MITRE·06:20 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-34025?
The severity of CVE-2022-34025 is medium with a CVSS score of 6.1.
2
How does CVE-2022-34025 affect Vesta Control Panel?
CVE-2022-34025 affects Vesta Control Panel version 1.0.0-5.
3
What is the vulnerability type of CVE-2022-34025?
CVE-2022-34025 is a cross-site scripting (XSS) vulnerability.
4
Where can I find more information about CVE-2022-34025?
You can find more information about CVE-2022-34025 at the following reference: [link](https://github.com/serghey-rodin/vesta/issues/2252)
5
How do I fix the cross-site scripting vulnerability in Vesta Control Panel?
To fix the cross-site scripting vulnerability in Vesta Control Panel, you should update to a version that patches the vulnerability.