CVE-2022-1536
Dashboard / Vulnerabilities / CVE-2022-1536
CVE-2022-1536
Summary: automad Dashboard cross site scripting
Details: A vulnerability has been found in automad up to 1.10.9 and classified as problematic. This vulnerability affects the Dashboard. The manipulation of the argument title with the input Home</title><script>alert("home")</script><title> leads to a cross site scripting. The attack can be initiated remotely but requires an authentication. The exploit details have disclosed to the public and may be used.
References: https://github.com/xiahao90/CVEproject/blob/main/xiahao.webray.com.cn/automad%3C%3D1.10.9%20Stored%20Cross-Site%20Scripting%28XSS%29.md, https://vuldb.com/?id.198706, https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/1xxx/CVE-2022-1536.json, https://nvd.nist.gov/vuln/detail/CVE-2022-1536
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
