CVE-2022-40408: XSS
FeehiCMS v2.1.1 was discovered to contain a cross-site scripting (XSS) vulnerability via a crafted payload injected into the Comment box under the Single Page module.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-40408?
The severity of CVE-2022-40408 is medium with a CVSS score of 5.4.
How does CVE-2022-40408 affect FeehiCMS?
CVE-2022-40408 affects FeehiCMS version 2.1.1 by allowing cross-site scripting (XSS) attacks through a crafted payload in the Comment box under the Single Page module.
How can I fix the CVE-2022-40408 vulnerability in FeehiCMS?
To fix the CVE-2022-40408 vulnerability in FeehiCMS, you should update to a version that has addressed the cross-site scripting (XSS) vulnerability.
Is there any reference or documentation available for CVE-2022-40408?
Yes, you can find more information about CVE-2022-40408 in the GitHub issue #3: https://github.com/liufee/feehicms/issues/3.
What CWE category does CVE-2022-40408 belong to?
CVE-2022-40408 belongs to the CWE category 79, which is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').