Record summary

CVE-2022-46888 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

Multiple reflective cross-site scripting (XSS) vulnerabilities in NexusPHP before 1.7.33 allow remote attackers to inject arbitrary web script or HTML via the secret parameter in /login.php; q parameter in /user-ban-log.php; query parameter in /log.php; text parameter in /moresmiles.php; q parameter in myhr.php; or id parameter in /viewrequests.php.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 3, 2025 · Source: CVE List

Nuclei templates

1
ProjectDiscoveryMEDIUMNexusPHP <1.7.33 - Cross-Site ScriptingCVSS 6.1

NexusPHP before 1.7.33 contains multiple cross-site scripting vulnerabilities via the secret parameter in /login.php; q parameter in /user-ban-log.php; query parameter in /log.php; text parameter in /moresmiles.php; q parameter in myhr.php; or id parameter in /viewrequests.php. An attacker can inject arbitrary web script or HTML, which can allow theft of cookie-based authentication credentials and launch of other attacks..

Impact

Attackers can inject malicious JavaScript through multiple parameters including secret in login.php, potentially stealing session cookies and credentials when users interact with crafted URLs in NexusPHP.

Remediation

Upgrade to NexusPHP version 1.7.33 or later to mitigate this vulnerability.

WeaknessesCWE-79
Authorsr3Y3r53
Template tagscvecve2022nexusphpnexusphpxssvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:nexusphp:nexusphp:*:*:*:*:*:*:*:*
Shodan: http.favicon.hash:-582931176
Shodan: cpe:"cpe:2.3:a:nexusphp:nexusphp"
FOFA: icon_hash=-582931176

Source: ProjectDiscovery

References

3