CVE-2022-36433
29.11.2022, 13:15
The blog-post creation functionality in the Amasty Blog Pro 2.10.3 plugin for Magento 2 allows injection of JavaScript code in the short_content and full_content fields, leading to XSS attacks against admin panel users via posts/preview or posts/save.
Vendor | Product | Version |
---|---|---|
amasty | amasty_blog_pro | 𝑥 < 2.10.5 |
𝑥
= Vulnerable software versions