CVE-2022-36304: XSS
Published Jul 19, 2022
·Updated
Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the generateresponse function at /web/api/v1/upload/UploadHandler.php.
Affected Software
1 affected component
VestaCP Vesta Control Panel=1.0.0-5
Event History
Jul 19, 2022
CVE Published
via MITRE·06:20 PM
Data Sourced
via MITRE·06:20 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-36304.
2
What is the severity of CVE-2022-36304?
The severity of CVE-2022-36304 is medium with a CVSS score of 6.1.
3
What software version is affected by CVE-2022-36304?
Vesta Control Panel version 1.0.0-5 is affected by CVE-2022-36304.
4
What is the CWE ID for CVE-2022-36304?
The CWE ID for CVE-2022-36304 is CWE-79.
5
Is there a fix available for CVE-2022-36304?
Yes, please refer to the following link for more information on how to fix CVE-2022-36304: [link](https://github.com/serghey-rodin/vesta/issues/2252).