CVE-2022-24586
EUVD-2022-2946515.02.2022, 14:15
A stored cross-site scripting (XSS) vulnerability in the component /core/admin/categories.php of PluXml v5.8.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the content and thumbnail parameters.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| pluxml | pluxml | 5.8.7 |
𝑥
= Vulnerable software versions
Ubuntu Releases