Stored Cross-Site Scripting in Exment and Laravel Admin
CVE-2022-38089

5.4MEDIUM

Key Information:

Status
Vendor
CVE Published:
24 August 2022

What is CVE-2022-38089?

The vulnerability presents a stored cross-site scripting issue in Exment and Laravel Admin versions mentioned. This flaw allows a remote authenticated attacker to inject malicious scripts, potentially compromising user data and application integrity. Proper input validation and sanitization mechanisms are essential to mitigate this risk and ensure web application security.

Affected Version(s)

Exment (PHP8) exceedone/exment v5.0.2 and earlier and exceedone/laravel-admin v3.0.0 and earlier, (PHP7) exceedone/exment v4.4.2 and earlier and exceedone/laravel-admin v2.2.2 and earlier

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.