Cross-Site Scripting Vulnerability in Vesta by Serghey Rodin
CVE-2022-36304
6.1MEDIUM
What is CVE-2022-36304?
A cross-site scripting (XSS) vulnerability was identified in Vesta versions 1.0.0 to 1.0.5, specifically within the generate_response function located in /web/api/v1/upload/UploadHandler.php. This vulnerability could allow attackers to inject malicious scripts into web pages viewed by non-privileged users, leading to potential unauthorized actions or data exposure. Developers are urged to apply security updates promptly and validate user inputs to mitigate the risks associated with this vulnerability.
