CVE-2022-36305: XSS
Published Jul 19, 2022
·Updated
Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the body function at /web/api/v1/upload/UploadHandler.php.
Affected Software
1 affected component
VestaCP Vesta Control Panel=1.0.0-5
Event History
Jul 19, 2022
CVE Published
via MITRE·06:20 PM
Data Sourced
via MITRE·06:20 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-36305.
2
What is the severity level of CVE-2022-36305?
The severity level of CVE-2022-36305 is medium.
3
How does CVE-2022-36305 affect Vesta Control Panel?
CVE-2022-36305 affects Vesta Control Panel version 1.0.0-5.
4
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-79.
5
How can I fix CVE-2022-36305 in Vesta Control Panel?
To fix CVE-2022-36305, you should update Vesta Control Panel to a version that has the patch for this vulnerability.