Vulnerabilities > Amasty > Amasty Blog PRO > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-11-29 CVE-2022-36433 Cross-site Scripting vulnerability in Amasty Blog PRO 2.10.3
The blog-post creation functionality in the Amasty Blog Pro 2.10.3 plugin for Magento 2 allows injection of JavaScript code in the short_content and full_content fields, leading to XSS attacks against admin panel users via posts/preview or posts/save.
network
low complexity
amasty CWE-79
6.1