CVE-2022-25410 describes a stored cross-site scripting (XSS) vulnerability in Maxsite CMS v180, specifically affecting the /admin/files component through the f_file_description parameter. This medium-severity vulnerability (CVSS 5.4) requires low privileges and user interaction, allowing an attacker to inject malicious scripts that could lead to information disclosure or defacement. While the EPSS score is low, indicating a low probability of exploitation, there is currently no public exploit code available, nor any evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
108CPE matchmatch criteria | cpe:2.3:a:max-3000:maxsite_cms:108:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.