6.1
CVSSv3

CVE-2022-46391

Published: 04/12/2022 Updated: 07/11/2023
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

AWStats 7.x up to and including 7.8 allows XSS in the hostinfo plugin due to printing a response from Net::XWhois without proper checks.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

awstats awstats

debian debian linux 10.0

fedoraproject fedora 36

fedoraproject fedora 37

Vendor Advisories

Debian Bug report logs - #1025410 awstats: CVE-2022-46391: XSS due to printing response from Net::XWhois without proper checks Package: src:awstats; Maintainer for src:awstats is Debian QA Group <packages@qadebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 4 Dec 2022 09:33:02 UTC Severit ...