CVE-2022-37059: XSS
Published Aug 29, 2022
·Updated
Cross Site Scripting (XSS) in Admin Panel of Subrion CMS 4.2.1 allows attacker to inject arbitrary code via Login Field
Affected Software
1 affected component
Intelliants Subrion CMS=4.2.1
Event History
Aug 29, 2022
CVE Published
via MITRE·12:54 PM
Data Sourced
via MITRE·12:54 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-37059?
The severity of CVE-2022-37059 is medium with a CVSS score of 4.8.
2
How does CVE-2022-37059 affect Subrion CMS?
CVE-2022-37059 allows an attacker to inject arbitrary code via the Login Field in the Admin Panel of Subrion CMS 4.2.1.
3
How can an attacker exploit CVE-2022-37059?
An attacker can exploit CVE-2022-37059 by injecting arbitrary code into the Login Field of the Admin Panel to perform Cross-Site Scripting (XSS) attacks.
4
Is there a fix available for CVE-2022-37059?
Yes, an update to Subrion CMS version 4.2.2 or newer addresses the vulnerability and should be applied.
5
Where can I find more information about CVE-2022-37059?
More information about CVE-2022-37059 can be found at the following URL: https://drive.google.com/file/d/1lmU8zuyzyC9LHFXuXzamnkcLcjcfs0xE/view?usp=sharing