CVE-2022-40408

MEDIUM5.4EPSS 0.30%

FeehiCMS vulnerable to Cross-Site scripting via crafted payload

Published: 9/30/2022Modified: 11/8/2023
Also known as:GHSA-5mqq-7g25-r4wx

Description

FeehiCMS versions 2.0.1.1 and prior contain a cross-site scripting (XSS) vulnerability via a crafted payload injected into the Comment box under the Single Page module. There are no patches and no known workarounds for this issue.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM5.4CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

References (3)