CVE-2022-42486: XSS
Published Dec 7, 2022
·Updated
Stored cross-site scripting vulnerability in User group management of baserCMS versions prior to 4.7.2 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script.
Affected Software
1 affected component
baserCMS BaserCMS<4.7.2
Event History
Dec 7, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·04:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-42486?
CVE-2022-42486 is a stored cross-site scripting vulnerability in the User group management of baserCMS versions prior to 4.7.2.
2
How does CVE-2022-42486 impact baserCMS?
CVE-2022-42486 allows a remote authenticated attacker with administrative privileges to inject an arbitrary script.
3
What is the severity of CVE-2022-42486?
CVE-2022-42486 has a severity rating of medium with a CVSS score of 4.8.
4
How can I fix CVE-2022-42486?
To fix CVE-2022-42486, upgrade to baserCMS version 4.7.2 or higher.
5
Where can I find more information about CVE-2022-42486?
You can find more information about CVE-2022-42486 on the baserCMS security advisory page and the JVN website.