CVE-2022-46391: XSS
Published Dec 4, 2022
·Updated
AWStats 7.x through 7.8 allows XSS in the hostinfo plugin due to printing a response from Net::XWhois without proper checks.
Affected Software
4 affected components
Awstats AWStats>=7.0<=7.8
Debian Debian Linux=10.0
Fedoraproject Fedora=36
Fedoraproject Fedora=37
Remediation
Patch Available
Event History
Dec 4, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-46391.
2
What is the severity of CVE-2022-46391?
The severity of CVE-2022-46391 is medium.
3
What software versions are affected by CVE-2022-46391?
AWStats 7.x through 7.8, Debian Linux 10.0, Fedora 36, and Fedora 37 are affected by CVE-2022-46391.
4
What is the CWE ID for CVE-2022-46391?
The CWE ID for CVE-2022-46391 is CWE-79.
5
How can I fix CVE-2022-46391?
To fix CVE-2022-46391, update to the latest version of AWStats and apply any available patches or security updates for your operating system.