Stored Cross-Site Scripting Vulnerability in Feehi CMS by Liufee
CVE-2022-34140
5.4MEDIUM
What is CVE-2022-34140?
A stored cross-site scripting (XSS) vulnerability exists in the Feehi CMS version 2.1.1, specifically in the signup functionality located at /index.php?r=site%2Fsignup. This vulnerability allows attackers to execute arbitrary web scripts or HTML by injecting a crafted payload into the username input field. This can result in unauthorized script execution, potentially compromising user data and leading to further exploitation of the application.
