Reflected Cross-Site Scripting Vulnerabilities in Maccms v10 by Magicblack
CVE-2022-26573

6.1MEDIUM

Key Information:

Vendor

Maccms

Status
Vendor
CVE Published:
25 March 2022

What is CVE-2022-26573?

Maccms version 10 has been found to contain multiple reflected cross-site scripting (XSS) vulnerabilities. These vulnerabilities occur through the handling of select and input parameters in the /admin.php/admin/art/data.html endpoint. Attackers can exploit these weaknesses to execute arbitrary scripts in the context of an affected user's session, potentially leading to unauthorized actions or data exposure.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.