Lucene search

K
nvd[email protected]NVD:CVE-2022-37731
HistorySep 07, 2022 - 3:15 p.m.

CVE-2022-37731

2022-09-0715:15:08
CWE-79
web.nvd.nist.gov
3
ftcms 2.1
xss
poster.php
javascript
web page
user
administrator
malicious code

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

34.0%

ftcms 2.1 poster.PHP has a XSS vulnerability. The attacker inserts malicious JavaScript code into the web page, causing the user / administrator to trigger malicious code when accessing.

Affected configurations

Nvd
Node
ftcmsftcmsMatch2.1
VendorProductVersionCPE
ftcmsftcms2.1cpe:2.3:a:ftcms:ftcms:2.1:*:*:*:*:*:*:*

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

34.0%

Related for NVD:CVE-2022-37731