MEDIUM
htmly Edit Profile Module cross site scripting
Published Mar 29, 2022
5.4
MEDIUMCVSS 3.1
EPSS 0.94%
Description
A vulnerability, which was classified as problematic, has been found in htmly 5.3 whis affects the component Edit Profile Module. The manipulation of the field Title with script tags leads to persistent cross site scripting. The attack may be initiated remotely and requires an authentication. A simple POC has been disclosed to the public and may be used.
Affected products
- Vendor n/a Product Htmly Defaultn/a
- Version 5.3StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Htmly | n/a |
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-24431 Advisory
- https://github.com/liaojia-99/project/blob/main/htmly/1.md x_refsource_MISCExploitThird Party Advisory
- https://github.com/liaojia-99/project/tree/main/htmly x_refsource_MISCExploitThird Party Advisory
- https://vuldb.com/?id.195203 x_refsource_MISCThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-24431 | Advisory | |
| https://github.com/liaojia-99/project/blob/main/htmly/1.md | x_refsource_MISCExploitThird Party Advisory | |
| https://github.com/liaojia-99/project/tree/main/htmly | x_refsource_MISCExploitThird Party Advisory | |
| https://vuldb.com/?id.195203 | x_refsource_MISCThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Mar 29, 2022
Updated Apr 15, 2025
Reserved Mar 25, 2022
Link CVE-2022-1087
CISA Vulnrichment
Updated Apr 14, 2025
ENISA EUVD
EUVD-2022-24431 Assigner VulDB
Published Mar 29, 2022
Updated Apr 15, 2025
Exploited since n/a
Link EUVD-2022-24431