CVE-2022-40849
Last modified
CVE-2022-40849 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. ThinkCMF version 6.0.7 is affected by Stored Cross-Site Scripting (XSS). An attacker who successfully exploited this vulnerability could inject a Persistent XSS payload in the Slideshow Management section that execute arbitrary JavaScript code on the client side, e.g., to steal the administrator's PHP session token (PHPSESSID).. EPSS estimates a 0.39% chance of exploitation in the next 30 days.
Description
ThinkCMF version 6.0.7 is affected by Stored Cross-Site Scripting (XSS). An attacker who successfully exploited this vulnerability could inject a Persistent XSS payload in the Slideshow Management section that execute arbitrary JavaScript code on the client side, e.g., to steal the administrator's PHP session token (PHPSESSID).
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Thinkcmf | Thinkcmf | 6.0.7 |
References
- https://github.com/thinkcmf/thinkcmf/issues/737Exploit, Issue Tracking, Third Party Advisory
- https://github.com/thinkcmf/thinkcmf/issues/737Exploit, Issue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-40849?
How severe is CVE-2022-40849?
How do I fix CVE-2022-40849?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-40842ndk design NdkAdvancedCustomizationFields 3.5.0 is vulnerabl…9.1
- CVE-2022-40843The Tenda AC1200 V-W15Ev2 V15.11.0.10(1576) router is vulner…4.9
- CVE-2022-40844In Tenda (Shenzhen Tenda Technology Co., Ltd) AC1200 Router …5.4
- CVE-2022-40845The Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576) is af…6.5
- CVE-2022-40846In Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576), a Sto…4.8
- CVE-2022-40847In Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576), there…7.8
- CVE-2022-4085Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2022-40851Tenda AC15 V15.03.05.19 contained a stack overflow via the f…9.8
- CVE-2022-40853Tenda AC15 router V15.03.05.19 contains a stack overflow via…9.8
- CVE-2022-40854Tenda AC18 router contained a stack overflow vulnerability i…9.8
- CVE-2022-40855Tenda W20E router V15.11.0.6 contains a stack overflow in th…9.8
- CVE-2022-4086Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
Are you affected by CVE-2022-40849?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
