CVE-2022-41994: XSS
Stored cross-site scripting vulnerability in Permission Settings of baserCMS versions prior to 4.7.2 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-41994.
What is the title of the vulnerability?
The title of the vulnerability is 'Stored cross-site scripting vulnerability in Permission Settings of baserCMS versions prior to 4.7.2.'
What is the description of the vulnerability?
The vulnerability is a stored cross-site scripting vulnerability in the Permission Settings of baserCMS versions prior to 4.7.2, which allows a remote authenticated attacker with administrative privilege to inject an arbitrary script.
What is the severity of CVE-2022-41994?
The severity of CVE-2022-41994 is medium with a CVSS score of 4.8.
What software versions are affected by CVE-2022-41994?
baserCMS versions prior to 4.7.2 are affected by CVE-2022-41994.
How can an attacker exploit this vulnerability?
A remote authenticated attacker with administrative privilege can exploit the vulnerability by injecting an arbitrary script through the Permission Settings.
How can I fix CVE-2022-41994?
To fix CVE-2022-41994, update baserCMS to version 4.7.2 or later.
Where can I find more information about CVE-2022-41994?
You can find more information about CVE-2022-41994 at the following references: [Link 1](https://basercms.net/security/JVN_53682526), [Link 2](https://jvn.jp/en/jp/JVN53682526/index.html)
What is the CWE ID of CVE-2022-41994?
The CWE ID of CVE-2022-41994 is 79, which represents Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').