CVE-2022-38080: XSS
Reflected cross-site scripting vulnerability in Exment ((PHP8) exceedone/exment v5.0.2 and earlier and exceedone/laravel-admin v3.0.0 and earlier, (PHP7) exceedone/exment v4.4.2 and earlier and exceedone/laravel-admin v2.2.2 and earlier) allows a remote authenticated attacker to inject an arbitrary script.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-38080?
CVE-2022-38080 is a reflected cross-site scripting vulnerability in Exment ((PHP8) exceedone/exment v5.0.2 and earlier and exceedone/laravel-admin v3.0.0 and earlier, (PHP7) exceedone/exment v4.4.2 and earlier and exceedone/laravel-admin v2.2.2 and earlier) that allows a remote authenticated attacker to inject arbitrary code.
What type of vulnerability is CVE-2022-38080?
CVE-2022-38080 is a reflected cross-site scripting vulnerability.
How severe is CVE-2022-38080?
CVE-2022-38080 has a severity rating of 5.4 (Medium).
Which software versions are affected by CVE-2022-38080?
CVE-2022-38080 affects Exment (PHP8) v5.0.2 and earlier, Exment (PHP7) v4.4.2 and earlier, Laravel-admin v3.0.0 and earlier, and Laravel-admin v2.2.2 and earlier.
How can I fix CVE-2022-38080?
To fix CVE-2022-38080, it is recommended to upgrade to Exment v5.0.3 or later, Exment v4.4.3 or later, Laravel-admin v3.0.1 or later, or Laravel-admin v2.2.3 or later.