Stored Cross-Site Scripting Vulnerability in FUEL-CMS by Daylight Studio
CVE-2022-28599

5.4MEDIUM

Key Information:

Status
Vendor
CVE Published:
3 May 2022

What is CVE-2022-28599?

A stored cross-site scripting (XSS) vulnerability in FUEL-CMS version 1.5.1 allows authenticated users to upload a malicious PDF file that serves as a stored XSS payload. If this payload is activated by an administrator, it can lead to an XSS attack, compromising the integrity of the application and its data.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.