First published: Thu Jan 18 2024(Updated: )
FlyCms 1.0 is vulnerable to Cross Site Scripting (XSS) in the system website settings website name section.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
FlyCms | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-22548 has a medium severity due to its potential for Cross Site Scripting (XSS) attacks.
To fix CVE-2024-22548, sanitize all inputs in the website settings section of FlyCms 1.0 to prevent XSS attacks.
CVE-2024-22548 can allow attackers to inject malicious scripts into the system website settings, compromising user data and website integrity.
CVE-2024-22548 specifically affects FlyCms version 1.0 and does not apply to other versions.
You can determine vulnerability by checking if your FlyCms instance is running version 1.0 and examining the website name field for XSS susceptibility.