CVE-2022-38089: XSS
Stored cross-site scripting vulnerability in Exment ((PHP8) exceedone/exment v5.0.2 and earlier and exceedone/laravel-admin v3.0.0 and earlier, (PHP7) exceedone/exment v4.4.2 and earlier and exceedone/laravel-admin v2.2.2 and earlier) allows a remote authenticated attacker to inject an arbitrary script.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-38089?
CVE-2022-38089 is a stored cross-site scripting vulnerability in Exment, a PHP application, allowing a remote authenticated attacker to inject arbitrary script code.
What is the severity of CVE-2022-38089?
The severity of CVE-2022-38089 is medium, with a CVSS score of 5.4.
Which software versions are affected by CVE-2022-38089?
Exment v5.0.2 and earlier, Laravel-admin v3.0.0 and earlier are affected by CVE-2022-38089.
How can a remote attacker exploit CVE-2022-38089?
A remote authenticated attacker can exploit CVE-2022-38089 by injecting arbitrary script code through the vulnerable Exment application.
Are there any references related to CVE-2022-38089?
Yes, you can find more information about CVE-2022-38089 in the following references: [Reference 1](https://exment.net/docs/#/release_note?id=v503-20220817), [Reference 2](https://exment.net/docs/#/weakness/20220817), [Reference 3](https://jvn.jp/en/jp/JVN46239102/index.html).