Reflected Cross-Site Scripting Vulnerability in Maccms by Magicblack
CVE-2022-27886
6.1MEDIUM
What is CVE-2022-27886?
A reflected cross-site scripting (XSS) vulnerability has been identified in Maccms v10, specifically affecting the /admin.php/admin/ulog/index.html endpoint through the wd parameter. This issue could allow an attacker to inject malicious scripts into web pages viewed by users, posing a significant risk to web application security. It is essential for users of Maccms to apply necessary patches and follow security best practices to mitigate the impact of this vulnerability.
