Reflected Cross-Site Scripting Vulnerabilities in Maccms v10 by Maccms
CVE-2022-27885
6.1MEDIUM
What is CVE-2022-27885?
Maccms v10 has been found to have multiple reflected cross-site scripting vulnerabilities within its administrative interface. These vulnerabilities are triggered through the select and input parameters in the /admin.php/admin/website/data.html endpoint. If exploited, these XSS vulnerabilities could allow an attacker to execute arbitrary scripts in the context of a user's browser session, potentially leading to unauthorized actions and data theft.
