CVE-2022-4640

Source
https://cve.org/CVERecord?id=CVE-2022-4640
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-4640.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-4640
Aliases
Published
2022-12-21T00:00:00Z
Modified
2026-07-15T01:48:52.024694357Z
Severity
  • 3.5 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N CVSS Calculator
Summary
Mingsoft MCMS Article save cross site scripting
Details

A vulnerability has been found in Mingsoft MCMS 5.2.9 and classified as problematic. Affected by this vulnerability is the function save of the component Article Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-216499.

Database specific
{
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "5.2.9"
                },
                {
                    "last_affected": "5.2.9"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ],
    "cwe_ids": [
        "CWE-707"
    ],
    "cna_assigner": "VulDB",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/4xxx/CVE-2022-4640.json"
}
References

Affected packages

Git / github.com/ming-soft/mcms

Affected ranges

Type
GIT
Repo
https://github.com/ming-soft/mcms
Events
Database specific
{
    "cpe": "cpe:2.3:a:mingsoft:mcms:5.2.9:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "5.2.9"
        },
        {
            "last_affected": "5.2.9"
        }
    ],
    "source": "CPE_STRING"
}

Affected versions

5.*
5.2.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-4640.json"