Cross-Site Scripting Vulnerabilities in Gibbon CMS
CVE-2022-23871

5.4MEDIUM

Key Information:

Vendor

Gibbonedu

Status
Vendor
CVE Published:
3 February 2022

What is CVE-2022-23871?

Multiple cross-site scripting (XSS) vulnerabilities exist in the 'outcomes_addProcess.php' component of Gibbon CMS v22.0.01. These vulnerabilities enable attackers to execute arbitrary web scripts or inject HTML code by submitting specially crafted payloads through the 'name', 'category', and 'description' parameters, potentially compromising user data and website integrity.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.