CVE-2022-43121: XSS
Published Nov 9, 2022
·Updated
A cross-site scripting (XSS) vulnerability in the CMS Field Add page of Intelliants Subrion CMS v4.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the tooltip text field.
Affected Software
1 affected component
Intelliants Subrion CMS=4.2.1
Event History
Nov 9, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this cross-site scripting (XSS) vulnerability?
The vulnerability ID for this cross-site scripting (XSS) vulnerability is CVE-2022-43121.
2
What is the affected software for this vulnerability?
The affected software for this vulnerability is Intelliants Subrion CMS v4.2.1.
3
What is the severity level of CVE-2022-43121?
The severity level of CVE-2022-43121 is medium (6.1).
4
How does this vulnerability allow attackers to execute arbitrary web scripts or HTML?
Attackers can execute arbitrary web scripts or HTML through a crafted payload injected into the tooltip text field on the CMS Field Add page of Intelliants Subrion CMS v4.2.1.
5
Is there any additional reference available for CVE-2022-43121?
Yes, you can refer to the following link for additional information: https://github.com/intelliants/subrion/issues/895.