logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2022-40849

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2022-40849

Description:
ThinkCMF version 6.0.7 is affected by Stored Cross-Site Scripting (XSS). An attacker who successfully exploited this vulnerability could inject a Persistent XSS payload in the Slideshow Management section that execute arbitrary JavaScript code on the client side, e.g., to steal the administrator's PHP session token (PHPSESSID).
Last updated date:
12/02/2022
Type:
exploit
Confidence:
HIGH
Date of publishing:
12/02/2022
Reference url to background

https://github.com/thinkcmf/thinkcmf/issues/737

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy