NA

CVE-2022-37721

Published: 25/11/2022 Updated: 29/11/2022
CVSS v3 Base Score: 9 | Impact Score: 6 | Exploitability Score: 2.3
VMScore: 0

Vulnerability Summary

PyroCMS 3.9 is vulnerable to a stored Cross Site Scripting (XSS_ when a low privileged user such as an author, injects a crafted html and javascript payload in a blog post, leading to full admin account takeover or privilege escalation.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

pyrocms pyrocms 3.9