Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-39145 | The blog-post creation functionality in the Amasty Blog Pro 2.10.3 plugin for Magento 2 allows injection of JavaScript code in the short_content and full_content fields, leading to XSS attacks against admin panel users via posts/preview or posts/save. |
| Link | Providers |
|---|---|
| https://github.com/afine-com/CVE-2022-36433 |
|
| https://weglow.ski |
|
Fri, 25 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-04-25T14:56:39.460Z
Reserved: 2022-07-25T00:00:00.000Z
Link: CVE-2022-36433
Updated: 2024-08-03T10:07:33.105Z
Status : Modified
Published: 2022-11-29T13:15:10.420
Modified: 2025-04-25T15:15:30.917
Link: CVE-2022-36433
No data.
OpenCVE Enrichment
No data.
EUVD