CVE-2022-37250: XSS
Published Sep 16, 2022
·Updated
Craft CMS 4.2.0.1 suffers from Stored Cross Site Scripting (XSS) in /admin/myaccount.
Affected Software
1 affected component
Craft CMS=4.2.0.1
Remediation
Patch Available
Event History
Sep 16, 2022
CVE Published
via MITRE·02:57 PM
Data Sourced
via MITRE·02:57 PM
Description
Data Sourced
via NVD·03:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-37250?
The severity of CVE-2022-37250 is medium with a CVSS score of 5.4.
2
What vulnerability does CVE-2022-37250 have?
CVE-2022-37250 has a stored Cross-Site Scripting (XSS) vulnerability.
3
What is the affected software version of CVE-2022-37250?
The affected software version of CVE-2022-37250 is Craft CMS 4.2.0.1.
4
How can I fix CVE-2022-37250?
To fix CVE-2022-37250, update Craft CMS to a version that has the security patch applied.
5
Where can I find more information about CVE-2022-37250?
More information about CVE-2022-37250 can be found at the following references: [GitHub](https://github.com/craftcms/cms/commit/cdc9cb66d0716c9552e4113c8e426fd1a31f9516), [Integrity](https://labs.integrity.pt/advisories/cve-2022-37250/).