First published: Fri Nov 25 2022(Updated: )
PyroCMS 3.9 is vulnerable to a stored Cross Site Scripting (XSS_ when a low privileged user such as an author, injects a crafted html and javascript payload in a blog post, leading to full admin account takeover or privilege escalation.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Pyrocms Pyrocms | =3.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-37721 is a stored Cross Site Scripting (XSS) vulnerability in PyroCMS 3.9.
The vulnerability occurs when a low privileged user injects a crafted html and javascript payload in a blog post in PyroCMS 3.9.
The impact of CVE-2022-37721 is a full admin account takeover or privilege escalation.
To fix the CVE-2022-37721 vulnerability, update PyroCMS to version 3.9.1 or apply the necessary patches.
CVE-2022-37721 has a severity level of critical.