CVE-2022-37430

MEDIUM5.4EPSS 0.32%

Stored XSS using uppercase characters in HTMLEditor

Published: 11/21/2022Modified: 2/20/2024
Also known as:GHSA-qw4w-vq8v-2wcv

Description

A malicious content author could add a Javascript payload to the href attribute of a link. A similar issue was identified and fixed via CVE-2022-28803. However, the fix didn't account for the casing of the href attribute. An attacker must have access to the CMS to exploit this issue.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM5.4CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

References (6)