Stored Cross-Site Scripting Vulnerability in baserCMS by baserCMS Community
CVE-2022-41994
4.8MEDIUM
What is CVE-2022-41994?
A stored cross-site scripting vulnerability exists in the permission settings of baserCMS, affecting all versions prior to 4.7.2. An authenticated attacker with administrative privileges can exploit this flaw to inject arbitrary scripts into the application. If successful, this could lead to malicious scripts being executed in the context of the user's browser, potentially compromising sensitive data or leading to further security breaches.
Affected Version(s)
baserCMS versions prior to 4.7.2
