CVE-2022-34140: XSS
Published Jul 27, 2022
·Updated
A stored cross-site scripting (XSS) vulnerability in /index.php?r=site%2Fsignup of Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username field.
Affected Software
1 affected component
Feehi Feehi CMS=2.1.1
Event History
Jul 27, 2022
CVE Published
via MITRE·11:44 PM
Data Sourced
via MITRE·11:44 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-34140?
The severity of CVE-2022-34140 is classified as high due to the potential for executing arbitrary web scripts.
2
How do I fix CVE-2022-34140?
To fix CVE-2022-34140, upgrade Feehi CMS to version 2.1.2 or later, which addresses this stored XSS vulnerability.
3
What type of vulnerability is CVE-2022-34140?
CVE-2022-34140 is a stored cross-site scripting (XSS) vulnerability found in Feehi CMS.
4
Can CVE-2022-34140 affect my website's security?
Yes, CVE-2022-34140 can significantly compromise your website's security by allowing attackers to inject malicious scripts.
5
Where does CVE-2022-34140 exist in Feehi CMS?
CVE-2022-34140 exists in the signup functionality at /index.php?r=site%2Fsignup of Feehi CMS v2.1.1.