CVE-2022-1526
Dashboard / Vulnerabilities / CVE-2022-1526
CVE-2022-1526
Summary: Emlog Pro POST Parameter cross site scripting
Details: A vulnerability, which was classified as problematic, was found in Emlog Pro up to 1.2.2. This affects the POST parameter handling of articles. The manipulation with the input <script>alert(1);</script> leads to cross site scripting. It is possible to initiate the attack remotely but it requires a signup and login by the attacker. The exploit has been disclosed to the public and may be used.
References: https://github.com/xiahao90/CVEproject/blob/main/xiahao.webray.com.cn/emlog%3C=pro-1.2.2%20Stored%20Cross-Site%20Scripting%28XSS%29.md, https://vuldb.com/?id.198705, https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/1xxx/CVE-2022-1526.json, https://nvd.nist.gov/vuln/detail/CVE-2022-1526
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
