CVE-2022-40000: XSS
Published Dec 15, 2022
·Updated
Cross Site Scripting (XSS) vulnerability in FeehiCMS-2.1.1 allows remote attackers to run arbitrary code via the username field of the admin log in page.
Affected Software
1 affected component
Feehi Feehicms=2.1.1
Event History
Dec 15, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-40000?
CVE-2022-40000 is classified as a medium severity vulnerability due to its potential for exploitation through Cross Site Scripting.
2
How do I fix CVE-2022-40000?
To fix CVE-2022-40000, update FeehiCMS to the latest version that addresses this vulnerability.
3
Who is affected by CVE-2022-40000?
Users of FeehiCMS version 2.1.1 are affected by CVE-2022-40000.
4
What kind of exploit is possible with CVE-2022-40000?
CVE-2022-40000 allows remote attackers to execute arbitrary code via the username field on the admin login page.
5
Is CVE-2022-40000 easily exploitable?
Yes, CVE-2022-40000 is considered easily exploitable by an attacker familiar with Cross Site Scripting techniques.