CVE-2022-44870: XSS
A reflected cross-site scripting (XSS) vulnerability in maccms10 v2022.1000.3032 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter under the AD Management module.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-44870?
CVE-2022-44870 is a reflected cross-site scripting (XSS) vulnerability in maccms10 v2022.1000.3032 that allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter under the AD Management module.
Which software version is affected by CVE-2022-44870?
Maccms10 v2022.1000.3032 is affected by CVE-2022-44870.
What is the severity of CVE-2022-44870?
The severity of CVE-2022-44870 is medium with a CVSS score of 6.1.
How can an attacker exploit CVE-2022-44870?
An attacker can exploit CVE-2022-44870 by injecting a crafted payload into the Name parameter under the AD Management module, allowing them to execute arbitrary web scripts or HTML.
Are there any references related to CVE-2022-44870?
Yes, you can find references related to CVE-2022-44870 at the following links: [Link 1](https://github.com/Cedric1314/CVE-2022-44870/blob/main/README.md), [Link 2](https://github.com/magicblack/maccms10/issues/986).