CVE-2022-37721

CRITICAL9.0EPSS 0.43%

PyroCMS vulnerable to stored Cross Site Scripting

Published: 11/25/2022Modified: 2/16/2024
Also known as:GHSA-cm7f-hf2g-ghrp

Description

PyroCMS 3.9 is vulnerable to a stored Cross Site Scripting (XSS) when a low privileged user, such as an author, injects a crafted html and javascript payload in a blog post, leading to full admin account takeover or privilege escalation.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1CRITICAL9.0CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

References (3)