First published: Fri Dec 09 2022(Updated: )
A vulnerability was found in S-CMS 5.0 Build 20220328. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Contact Information Page. The manipulation of the argument Make a Call leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-215197 was assigned to this vulnerability.
Credit: cna@vuldb.com cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
S-cms S-cms | =5.0 | |
=5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-4377 is medium with a score of 5.4.
The affected software of CVE-2022-4377 is S-CMS 5.0 Build 20220328.
CVE-2022-4377 is a cross-site scripting (XSS) vulnerability.
The CVE-2022-4377 vulnerability can be exploited by manipulating the 'Make a Call' argument in the Contact Information Page component.
Yes, you can find references for CVE-2022-4377 at the following links: [Link 1](https://github.com/mengdeyin/main/blob/main/README.md), [Link 2](https://vuldb.com/?id.215197).