Lucene search

K
cvelistMitreCVELIST:CVE-2022-40849
HistoryDec 01, 2022 - 12:00 a.m.

CVE-2022-40849

2022-12-0100:00:00
mitre
www.cve.org
1
thinkcmf
version 6.0.7
stored cross-site scripting
xss
slideshow management
javascript
php session token

0.001 Low

EPSS

Percentile

24.9%

ThinkCMF version 6.0.7 is affected by Stored Cross-Site Scripting (XSS). An attacker who successfully exploited this vulnerability could inject a Persistent XSS payload in the Slideshow Management section that execute arbitrary JavaScript code on the client side, e.g., to steal the administrator’s PHP session token (PHPSESSID).

0.001 Low

EPSS

Percentile

24.9%

Related for CVELIST:CVE-2022-40849