CVE-2022-40849

MEDIUM5.4EPSS 0.21%

ThinkCMF Stored Cross-Site Scripting (XSS)

Published: 12/1/2022Modified: 4/25/2024
Also known as:GHSA-m9mf-rqx6-2xpc

Description

ThinkCMF version 6.0.7 is affected by Stored Cross-Site Scripting (XSS). An attacker who successfully exploited this vulnerability could inject a Persistent XSS payload in the Slideshow Management section that execute arbitrary JavaScript code on the client side, e.g., to steal the administrator's PHP session token (PHPSESSID).

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM5.4CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

References (5)