First published: Wed Dec 21 2022(Updated: )
A vulnerability has been found in Mingsoft MCMS 5.2.9 and classified as problematic. Affected by this vulnerability is the function save of the component Article Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-216499.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mingsoft MCMS | =5.2.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-4640 is medium with a CVSS score of 5.4.
The affected software for CVE-2022-4640 is Mingsoft MCMS version 5.2.9.
CVE-2022-4640 is classified as problematic.
CVE-2022-4640 affects the 'save' function of the Article Handler component in Mingsoft MCMS, leading to cross-site scripting (XSS) vulnerabilities.
Yes, CVE-2022-4640 can be exploited remotely.
You can find more information about CVE-2022-4640 at the following references: [https://gitee.com/mingSoft/MCMS/issues/I65KI5](https://gitee.com/mingSoft/MCMS/issues/I65KI5) and [https://vuldb.com/?id.216499](https://vuldb.com/?id.216499).