CVE-2022-40001: XSS
Published Dec 15, 2022
·Updated
Cross Site Scripting (XSS) vulnerability in FeehiCMS-2.1.1 allows remote attackers to run arbitrary code via the title field of the create article page.
Affected Software
1 affected component
Feehi Feehicms=2.1.1
Event History
Dec 15, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-40001?
CVE-2022-40001 is considered a medium severity vulnerability due to its potential for remote code execution via XSS.
2
How do I fix CVE-2022-40001?
To fix CVE-2022-40001, upgrade FeehiCMS to version 2.1.2 or later where the XSS vulnerability has been patched.
3
What type of vulnerability is CVE-2022-40001?
CVE-2022-40001 is a Cross Site Scripting (XSS) vulnerability.
4
Who is affected by CVE-2022-40001?
Users of FeehiCMS version 2.1.1 are affected by CVE-2022-40001.
5
What can attackers do with CVE-2022-40001?
Attackers can exploit CVE-2022-40001 to run arbitrary code by injecting scripts into the title field on the create article page.