CVE-2022-40373

MEDIUM5.4EPSS 0.35%

FeehiCMS Cross Site Scripting vulnerability

Published: 12/15/2022Modified: 11/8/2023
Also known as:GHSA-xv8h-43h9-v3jq

Description

Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.1.1 allows remote attackers to run arbitrary code via upload of crafted XML file.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM5.4CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

References (3)