Persistent Cross-Site Scripting Vulnerability in XMPie UStore by XMPie
CVE-2022-23321
4.8MEDIUM
What is CVE-2022-23321?
A persistent cross-site scripting (XSS) vulnerability poses significant security risks within the XMPie UStore application. This flaw exists in two input fields located in the administrative panel where user details can be edited. An attacker could exploit this vulnerability to inject malicious scripts, compromising the integrity of the application and potentially gaining unauthorized access to sensitive data. It is crucial for administrators of XMPie UStore version 12.3.7244.0 to apply necessary security measures and updates to mitigate this security risk.