CVE-2022-40002: XSS
Published Dec 15, 2022
·Updated
Cross Site Scripting (XSS) vulnerability in FeehiCMS-2.1.1 allows remote attackers to run arbirtary code via the callback parameter to /cms/notify.
Affected Software
1 affected component
Feehi Feehicms=2.1.1
Event History
Dec 15, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-40002?
CVE-2022-40002 has a medium severity rating due to its potential for Cross Site Scripting attacks.
2
How do I fix CVE-2022-40002?
To fix CVE-2022-40002, upgrade FeehiCMS to a version higher than 2.1.1 where the vulnerability has been addressed.
3
What type of vulnerability is CVE-2022-40002?
CVE-2022-40002 is classified as a Cross Site Scripting (XSS) vulnerability.
4
Who is affected by CVE-2022-40002?
CVE-2022-40002 affects users of FeehiCMS version 2.1.1.
5
What can attackers do with CVE-2022-40002?
Attackers exploiting CVE-2022-40002 can execute arbitrary code via the callback parameter to /cms/notify.