Reflected Cross-Site Scripting Vulnerability in Maccms v10 by Magicblack
CVE-2022-27887
6.1MEDIUM
What is CVE-2022-27887?
Maccms v10 contains a reflected cross-site scripting (XSS) vulnerability that can be exploited through the 'repeat' parameter in the /admin.php/admin/vod/data.html endpoint. This flaw allows attackers to inject malicious scripts in the browser of an unsuspecting user, potentially leading to unauthorized actions and access to sensitive data.
