Stored Cross-Site Scripting Vulnerability in FUEL-CMS by Daylight Studio
CVE-2022-28599
5.4MEDIUM
What is CVE-2022-28599?
A stored cross-site scripting (XSS) vulnerability in FUEL-CMS version 1.5.1 allows authenticated users to upload a malicious PDF file that serves as a stored XSS payload. If this payload is activated by an administrator, it can lead to an XSS attack, compromising the integrity of the application and its data.
