CVE-2022-35174: XSS
Published Aug 18, 2022
·Updated
A stored cross-site scripting (XSS) vulnerability in Kirby's Starterkit v3.7.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Tags field.
Affected Software
1 affected component
getkirby Starterkit=3.7.0.2
Event History
Aug 18, 2022
CVE Published
via MITRE·05:27 PM
Data Sourced
via MITRE·05:27 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-35174?
CVE-2022-35174 is classified as a medium severity vulnerability due to its potential to allow attackers to execute arbitrary scripts.
2
How do I fix CVE-2022-35174?
To fix CVE-2022-35174, update the Kirby Starterkit to a patched version that addresses the stored cross-site scripting vulnerability.
3
What software is affected by CVE-2022-35174?
CVE-2022-35174 affects Kirby's Starterkit version 3.7.0.2.
4
What type of vulnerability is CVE-2022-35174?
CVE-2022-35174 is a stored cross-site scripting (XSS) vulnerability.
5
How can CVE-2022-35174 be exploited?
CVE-2022-35174 can be exploited by injecting malicious scripts into the Tags field, allowing execution of arbitrary code in a user's browser.