CVE-2022-38295: XSS
Published Sep 12, 2022
·Updated
Cuppa CMS v1.0 was discovered to contain a cross-site scripting vulnerability at /tablemanager/view/cuusergroups. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field under the Add New Group function.
Affected Software
1 affected component
CuppaCMS CuppaCMS=1.0
Event History
Sep 12, 2022
CVE Published
via MITRE·08:43 PM
Data Sourced
via MITRE·08:43 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-38295?
CVE-2022-38295 is classified as a cross-site scripting vulnerability that can lead to serious security risks.
2
How do I fix CVE-2022-38295?
To mitigate CVE-2022-38295, ensure proper input validation and sanitization for the Name field in the Add New Group function.
3
What systems are affected by CVE-2022-38295?
CVE-2022-38295 affects Cuppa CMS version 1.0.
4
What kind of attack can CVE-2022-38295 enable?
CVE-2022-38295 can enable attackers to execute arbitrary web scripts or HTML via crafted payloads.
5
When was CVE-2022-38295 discovered?
CVE-2022-38295 was discovered in Cuppa CMS v1.0.