CVE-2022-40373

MEDIUM

Feehicms - XSS

Title source: rule

Description

Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.1.1 allows remote attackers to run arbitrary code via upload of crafted XML file.

Scores

CVSS v3 5.4
EPSS 0.0035
EPSS Percentile 57.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
feehi/feehicms 2.1.1
feehi/feehicms 0Packagist
Published Dec 15, 2022
Tracked Since Feb 18, 2026