CVE-2022-40849

CVE-2022-40849

ThinkCMF version 6.0.7 is affected by Stored Cross-Site Scripting (XSS). An attacker who successfully exploited this vulnerability could inject a Persistent XSS payload in the Slideshow Management section that execute arbitrary JavaScript code on the client side, e.g., to steal the administrator’s PHP session token (PHPSESSID).

Source: CVE-2022-40849

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다