Vulnerability Details CVE-2022-38295
Cuppa CMS v1.0 was discovered to contain a cross-site scripting vulnerability at /table_manager/view/cu_user_groups. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field under the Add New Group function.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.451
EPSS Ranking 97.4%
CVSS Severity
CVSS v3 Score 6.1
Products affected by CVE-2022-38295
-
cpe:2.3:a:cuppacms:cuppacms:1.0