Ametys CMS v4.4.1 contains a persistent cross-site scripting vulnerability in the link directory's input fields for external links. Attackers can inject malicious script code in link text and descriptions to execute persistent attacks that compromise user sessions and manipulate application modules.
References
| Link | Resource |
|---|---|
| https://www.ametys.org/community/en/ametys-platform/ametys-portal/overview.html | Product |
| https://www.exploit-db.com/exploits/50692 | Exploit Third Party Advisory |
| https://www.vulncheck.com/advisories/ametys-cms-cross-site-scripting-xss | Third Party Advisory |
| https://www.vulnerability-lab.com/get_content.php?id=2275 | Exploit Third Party Advisory |
| https://www.exploit-db.com/exploits/50692 | Exploit Third Party Advisory |
| https://www.vulnerability-lab.com/get_content.php?id=2275 | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-01-13 23:15
Updated : 2026-02-02 16:16
NVD link : CVE-2022-50937
Mitre link : CVE-2022-50937
CVE.ORG link : CVE-2022-50937
JSON object : View
Products Affected
ametys
- ametys
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
