CVE-2022-36303: XSS
Published Jul 19, 2022
·Updated
Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the handlefileupload function at /web/api/v1/upload/UploadHandler.php.
Affected Software
1 affected component
VestaCP Vesta Control Panel=1.0.0-5
Event History
Jul 19, 2022
CVE Published
via MITRE·06:20 PM
Data Sourced
via MITRE·06:20 PM
Description
Frequently Asked Questions
1
What is CVE-2022-36303?
CVE-2022-36303 is a cross-site scripting (XSS) vulnerability found in Vesta v1.0.0-5.
2
What is the severity of CVE-2022-36303?
The severity of CVE-2022-36303 is rated as medium with a CVSS score of 6.1.
3
How does CVE-2022-36303 affect Vesta Control Panel?
CVE-2022-36303 affects Vesta Control Panel version 1.0.0-5.
4
How can CVE-2022-36303 be exploited?
CVE-2022-36303 can be exploited through the handle_file_upload function at /web/api/v1/upload/UploadHandler.php in Vesta v1.0.0-5.
5
Is there a patch available for CVE-2022-36303?
There is currently no patch available for CVE-2022-36303. It is recommended to follow the official GitHub repository for updates.