First published: Fri Nov 25 2022(Updated: )
A cross-site scripting (XSS) vulnerability in /admin/settings/save.php of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Website Footer field.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Wbce CMS | =1.5.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-45038 is a cross-site scripting (XSS) vulnerability in WBCE CMS v1.5.4 that allows attackers to execute arbitrary web scripts or HTML.
CVE-2022-45038 affects WBCE CMS v1.5.4 by enabling attackers to inject a crafted payload into the Website Footer field, resulting in the execution of arbitrary web scripts or HTML.
CVE-2022-45038 has a severity rating of medium (5.4) based on the Common Vulnerability Scoring System (CVSS).
To fix CVE-2022-45038 in WBCE CMS v1.5.4, it is recommended to upgrade to a version that includes a patch or fix provided by the WBCE CMS project. Additionally, input validation and sanitization of the Website Footer field should be implemented.
More information about CVE-2022-45038 can be found at the following reference: [link](https://shimo.im/docs/Ee32MrJd80iEwyA2)