leads to a cross s","datePublished":"2022-04-29T13:10:12+00:00","dateModified":"2025-04-15T14:40:54.853000+00:00","inLanguage":"en","author":{"@type":"Organization","name":"Vexday"},"publisher":{"@type":"Organization","name":"Vexday","url":"https://vexday.io"},"mainEntityOfPage":"https://vexday.io/en/cve/CVE-2022-1536","keywords":"CVE-2022-1536, CWE-79","breadcrumb":{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://vexday.io/en"},{"@type":"ListItem","position":2,"name":"CVE-2022-1536"}]}}</script><a class="backlink" href="/en">← back</a><article class="detail"><div class="cvh-head"><div class="cvh-tags"><span class="cid mono">CVE-2022-1536</span><span class="cvh-tag sev-low">low</span><a class="cvh-tag t-cwe" title="CWE-79 Cross Site Scripting" href="/en/cwe/CWE-79">CWE-79</a></div><h1>automad Dashboard cross site scripting</h1></div><div class="cvh-verdict cvh-low"><div class="cvh-score" style="color:var(--muted)">8<span>Vexday Risk Score</span></div><div class="cvh-div"></div><div class="cvh-say"><p>No sign of exploitation. No public exploitation artifact known so far.</p><div class="cvh-mini"><span>ssvc <b style="color:var(--muted)">Track</b></span><span>cvss <b>3.5</b></span><span>epss <b style="color:var(--orange)">0.7<!-- -->%</b></span></div></div></div><div class="cvh-metrics"><div class="cvh-m"><div class="cvh-m-l">exploitation probability</div><div class="cvh-m-v"><b style="color:var(--orange)">0.7%</b><span>top 50% of all CVEs</span></div><div class="cvh-bar"><span style="width:0.6649999999999999%"></span></div></div><div class="cvh-m"><div class="cvh-m-l">observed exploitation</div><div class="cvh-m-v"><b style="color:var(--muted)">no</b><span>no source reports it</span></div><div class="cvh-m-f"></div></div></div><div class="desc">A vulnerability has been found in automad up to 1.10.9 and classified as problematic. This vulnerability affects the Dashboard. The manipulation of the argument title with the input Home</title><script>alert("home")</script><title> leads to a cross site scripting. The attack can be initiated remotely but requires an authentication. The exploit details have disclosed to the public and may be used.</div><div class="vecbox">CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N</div><div class="block26"><div class="ph">Affected products</div><a class="pill" style="margin-right:8px;display:inline-block" href="/en/vendor/unspecified">unspecified · automad</a></div><div class="block26 reflist"><div class="ph">References</div><a href="https://github.com/xiahao90/CVEproject/blob/main/xiahao.webray.com.cn/automad%3C%3D1.10.9%20Stored%20Cross-Site%20Scripting%28XSS%29.md" target="_blank" rel="noopener noreferrer nofollow">https://github.com/xiahao90/CVEproject/blob/main/xiahao.webray.com.cn/automad%3C%3D1.10.9%20Stored%20Cross-Site%20Scripting%28XSS%29.md</a><a href="https://vuldb.com/?id.198706" target="_blank" rel="noopener noreferrer nofollow">https://vuldb.com/?id.198706</a></div></article></div></main><footer><div class="wrap"><nav class="fnav"><a data-ga="vexgraph_open" data-ga-src="footer" href="/en/vexgraph">VexGraph</a><a data-ga="live_open" data-ga-src="footer" href="/en/live">Live</a><a data-ga="boletim_open" data-ga-src="footer" href="/en/boletim">Briefing</a><a href="/en/panorama">Overview</a><a href="/en/search">CVEs</a><a href="/en/tech">Exposure by technology</a><a href="/en/vendors">Technologies</a><a href="/en/cwes">Weakness types</a><a data-ga="placar_open" data-ga-src="footer" href="/en/placar">Scoreboard</a><a data-ga="replay_open" data-ga-src="footer" href="/en/replay">Replay</a><a data-ga="api_docs_open" data-ga-src="footer" href="/en/api">API</a><a data-ga="feeds_open" data-ga-src="footer" href="/en/feeds">RSS</a><a href="/en/privacidade">Privacy</a></nav><div class="nvd">Vexday · um projeto <a href="https://truehacking.ai" data-ga="truehacking_cta" data-ga-location="footer" data-ga-dest="agent">TrueHacking</a>.</div></div></footer><script src="/_next/static/chunks/webpack-3cba8b0ee4f205f3.js" async=""></script><script>(self.__next_f=self.__next_f||[]).push([0]);self.__next_f.push([2,null])</script><script>self.__next_f.push([1,"1:HL[\"/_next/static/css/c36d54f802269755.css\",\"style\"]\n2:HL[\"/_next/static/css/03d82a0db5c8122c.css\",\"style\"]\n3:HL[\"/_next/static/css/55e767eb5e3cdc20.css\",\"style\"]\n"])</script><script>self.__next_f.push([1,"4:I[5751,[],\"\"]\n7:I[9275,[],\"\"]\na:I[1343,[],\"\"]\nb:I[1562,[\"231\",\"static/chunks/231-9e11bdfe3b664aec.js\",\"2986\",\"static/chunks/2986-44797c37049211bc.js\",\"1084\",\"static/chunks/app/%5Blang%5D/layout-87badba4d96c815d.js\"],\"default\"]\nc:I[231,[\"231\",\"static/chunks/231-9e11bdfe3b664aec.js\",\"4053\",\"static/chunks/app/%5Blang%5D/cve/%5Bid%5D/page-20227e05c7c03752.js\"],\"\"]\nd:I[3818,[\"231\",\"static/chunks/231-9e11bdfe3b664aec.js\",\"2986\",\"static/chunks/2986-44797c37049211bc.js\",\"1084\",\"static/chunks/app/%5Blang%5D/layout-87badba4d96c815d.js\"],\"default\"]\ne:I[7263,[\"3185\",\"static/chunks/app/layout-ec087375a8b9afad.js\"],\"default\"]\nf:I[4080,[\"3185\",\"static/chunks/app/layout-ec087375a8b9afad.js\"],\"\"]\n11:I[6130,[],\"\"]\n8:[\"lang\",\"en\",\"d\"]\n9:[\"id\",\"CVE-2022-1536\",\"d\"]\n12:[]\n"])</script><script>self.__next_f.push([1,"0:[[[\"$\",\"link\",\"0\",{\"rel\":\"stylesheet\",\"href\":\"/_next/static/css/c36d54f802269755.css\",\"precedence\":\"next\",\"crossOrigin\":\"$undefined\"}],[\"$\",\"link\",\"1\",{\"rel\":\"stylesheet\",\"href\":\"/_next/static/css/03d82a0db5c8122c.css\",\"precedence\":\"next\",\"crossOrigin\":\"$undefined\"}],[\"$\",\"link\",\"2\",{\"rel\":\"stylesheet\",\"href\":\"/_next/static/css/55e767eb5e3cdc20.css\",\"precedence\":\"next\",\"crossOrigin\":\"$undefined\"}]],[\"$\",\"$L4\",null,{\"buildId\":\"5UfyujLKVtXJyFk-ZelQB\",\"assetPrefix\":\"\",\"initialCanonicalUrl\":\"/en/cve/CVE-2022-1536\",\"initialTree\":[\"\",{\"children\":[[\"lang\",\"en\",\"d\"],{\"children\":[\"cve\",{\"children\":[[\"id\",\"CVE-2022-1536\",\"d\"],{\"children\":[\"__PAGE__\",{}]}]}]}]},\"$undefined\",\"$undefined\",true],\"initialSeedData\":[\"\",{\"children\":[[\"lang\",\"en\",\"d\"],{\"children\":[\"cve\",{\"children\":[[\"id\",\"CVE-2022-1536\",\"d\"],{\"children\":[\"__PAGE__\",{},[[\"$L5\",\"$L6\"],null],null]},[\"$\",\"$L7\",null,{\"parallelRouterKey\":\"children\",\"segmentPath\":[\"children\",\"$8\",\"children\",\"cve\",\"children\",\"$9\",\"children\"],\"error\":\"$undefined\",\"errorStyles\":\"$undefined\",\"errorScripts\":\"$undefined\",\"template\":[\"$\",\"$La\",null,{}],\"templateStyles\":\"$undefined\",\"templateScripts\":\"$undefined\",\"notFound\":\"$undefined\",\"notFoundStyles\":\"$undefined\",\"styles\":null}],null]},[\"$\",\"$L7\",null,{\"parallelRouterKey\":\"children\",\"segmentPath\":[\"children\",\"$8\",\"children\",\"cve\",\"children\"],\"error\":\"$undefined\",\"errorStyles\":\"$undefined\",\"errorScripts\":\"$undefined\",\"template\":[\"$\",\"$La\",null,{}],\"templateStyles\":\"$undefined\",\"templateScripts\":\"$undefined\",\"notFound\":\"$undefined\",\"notFoundStyles\":\"$undefined\",\"styles\":null}],null]},[[[\"$\",\"$Lb\",null,{\"lang\":\"en\",\"searchPh\":\"search CVE, vendor, CWE…\",\"liveLabel\":\"Live\",\"bolLabel\":\"Briefing\",\"panoramaLabel\":\"Overview\",\"cvesLabel\":\"CVEs\",\"threatsLabel\":\"Threats\",\"xtLabel\":\"Exploit Timeline\",\"toolsLabel\":\"Tools\",\"intelLabel\":\"Intelligence\",\"dataLabel\":\"Data\",\"vulnLabel\":\"Vulnerabilities\",\"biLabel\":\"Incidents\",\"biDesc\":\"Breaches with a confidence seal\",\"boardLabel\":\"Board Intelligence\",\"boardDesc\":\"The day's cyber risk in one number the board understands\",\"xpLabel\":\"Exploits\",\"xpDesc\":\"Cataloged PoCs, Nuclei and Metasploit\",\"raioxLabel\":\"X-Ray\",\"iocsLabel\":\"IOCs\",\"ipcLabel\":\"Check IP\",\"painelLabel\":\"My Dashboard\",\"vzLabel\":\"Email breach check\",\"rcLabel\":\"CVE risk calculator\",\"rcDesc\":\"real risk of a CVE\",\"sxLabel\":\"Exposure by sector\",\"sxDesc\":\"ransomware by sector in Brazil\",\"tbLabel\":\"Time-bomb CVEs\",\"tbDesc\":\"about to blow: patch now\",\"lxLabel\":\"Check shortened link\",\"lxDesc\":\"where does this link go?\",\"scLabel\":\"Check scam site\",\"scDesc\":\"fake store? check first\",\"phLabel\":\"Analyze phishing email\",\"phDesc\":\"is this email a scam?\",\"hdLabel\":\"Analyze email header\",\"hdDesc\":\"is the sender spoofed?\",\"actorsLabel\":\"Threat Actors\",\"brasilLabel\":\"Threats to Brazil\",\"xtDesc\":\"risk queue\",\"threatsDesc\":\"ransomware · malware\",\"panoramaDesc\":\"observatory\",\"rxDesc\":\"your stack vs. real attack\",\"ipcDesc\":\"IP reputation in seconds\",\"vzDesc\":\"breach monitoring\",\"painelDesc\":\"your exposure score\",\"actorsDesc\":\"524 groups tracked\",\"brasilDesc\":\"victims and groups in Brazil\",\"iocsDesc\":\"live attack indicators\",\"cvesDesc\":\"361k vulnerabilities\",\"bolDesc\":\"the day’s signal, at 9am\"}],[\"$\",\"main\",null,{\"children\":[\"$\",\"$L7\",null,{\"parallelRouterKey\":\"children\",\"segmentPath\":[\"children\",\"$8\",\"children\"],\"error\":\"$undefined\",\"errorStyles\":\"$undefined\",\"errorScripts\":\"$undefined\",\"template\":[\"$\",\"$La\",null,{}],\"templateStyles\":\"$undefined\",\"templateScripts\":\"$undefined\",\"notFound\":\"$undefined\",\"notFoundStyles\":\"$undefined\",\"styles\":null}]}],[\"$\",\"footer\",null,{\"children\":[\"$\",\"div\",null,{\"className\":\"wrap\",\"children\":[[\"$\",\"nav\",null,{\"className\":\"fnav\",\"children\":[[\"$\",\"$Lc\",null,{\"href\":\"/en/vexgraph\",\"data-ga\":\"vexgraph_open\",\"data-ga-src\":\"footer\",\"children\":\"VexGraph\"}],[\"$\",\"$Lc\",null,{\"href\":\"/en/live\",\"data-ga\":\"live_open\",\"data-ga-src\":\"footer\",\"children\":\"Live\"}],[\"$\",\"$Lc\",null,{\"href\":\"/en/boletim\",\"data-ga\":\"boletim_open\",\"data-ga-src\":\"footer\",\"children\":\"Briefing\"}],[\"$\",\"$Lc\",null,{\"href\":\"/en/panorama\",\"children\":\"Overview\"}],[\"$\",\"$Lc\",null,{\"href\":\"/en/search\",\"children\":\"CVEs\"}],[\"$\",\"$Lc\",null,{\"href\":\"/en/tech\",\"children\":\"Exposure by technology\"}],[\"$\",\"$Lc\",null,{\"href\":\"/en/vendors\",\"children\":\"Technologies\"}],[\"$\",\"$Lc\",null,{\"href\":\"/en/cwes\",\"children\":\"Weakness types\"}],[\"$\",\"$Lc\",null,{\"href\":\"/en/placar\",\"data-ga\":\"placar_open\",\"data-ga-src\":\"footer\",\"children\":\"Scoreboard\"}],[\"$\",\"$Lc\",null,{\"href\":\"/en/replay\",\"data-ga\":\"replay_open\",\"data-ga-src\":\"footer\",\"children\":\"Replay\"}],[\"$\",\"$Lc\",null,{\"href\":\"/en/api\",\"data-ga\":\"api_docs_open\",\"data-ga-src\":\"footer\",\"children\":\"API\"}],[\"$\",\"$Lc\",null,{\"href\":\"/en/feeds\",\"data-ga\":\"feeds_open\",\"data-ga-src\":\"footer\",\"children\":\"RSS\"}],[\"$\",\"$Lc\",null,{\"href\":\"/en/privacidade\",\"children\":\"Privacy\"}]]}],[\"$\",\"div\",null,{\"className\":\"nvd\",\"children\":[\"Vexday · um projeto \",[\"$\",\"a\",null,{\"href\":\"https://truehacking.ai\",\"data-ga\":\"truehacking_cta\",\"data-ga-location\":\"footer\",\"data-ga-dest\":\"agent\",\"children\":\"TrueHacking\"}],\".\"]}]]}]}],[\"$\",\"$Ld\",null,{\"lang\":\"en\",\"t\":{\"msg\":\"We use cookies to measure traffic and improve the site. You can accept or reject.\",\"accept\":\"Accept\",\"reject\":\"Reject\",\"more\":\"Learn more\"}}]],null],null]},[[\"$\",\"html\",null,{\"lang\":\"en\",\"suppressHydrationWarning\":true,\"children\":[[\"$\",\"head\",null,{\"children\":[[\"$\",\"script\",null,{\"dangerouslySetInnerHTML\":{\"__html\":\"(function(){\\nwindow.dataLayer=window.dataLayer||[];function gtag(){dataLayer.push(arguments);}window.gtag=window.gtag||gtag;\\ngtag('consent','default',{ad_storage:'denied',ad_user_data:'denied',ad_personalization:'denied',analytics_storage:'denied',functionality_storage:'granted',security_storage:'granted',wait_for_update:500});\\ngtag('set','ads_data_redaction',true);gtag('set','url_passthrough',true);\\ntry{if(localStorage.getItem('vd-consent')==='granted'){gtag('consent','update',{ad_storage:'granted',ad_user_data:'granted',ad_personalization:'granted',analytics_storage:'granted'});}}catch(e){}\\n})();\"}}],[\"$\",\"script\",null,{\"dangerouslySetInnerHTML\":{\"__html\":\"(function(){var t;try{t=localStorage.getItem(\\\"th-theme\\\");}catch(e){}\\nif(t!==\\\"light\\\"\u0026\u0026t!==\\\"dark\\\"){t=\\\"dark\\\";}\\ndocument.documentElement.setAttribute(\\\"data-theme\\\",t);\\nwindow.toggleTheme=function(){var d=document.documentElement;var n=d.getAttribute(\\\"data-theme\\\")===\\\"dark\\\"?\\\"light\\\":\\\"dark\\\";\\nd.setAttribute(\\\"data-theme\\\",n);try{localStorage.setItem(\\\"th-theme\\\",n);}catch(e){}};\\n})();\"}}],[\"$\",\"link\",null,{\"rel\":\"preconnect\",\"href\":\"https://www.googletagmanager.com\"}],[\"$\",\"link\",null,{\"rel\":\"preconnect\",\"href\":\"https://fonts.googleapis.com\"}],[\"$\",\"link\",null,{\"rel\":\"preconnect\",\"href\":\"https://fonts.gstatic.com\",\"crossOrigin\":\"\"}],[\"$\",\"link\",null,{\"href\":\"https://fonts.googleapis.com/css2?family=Newsreader:wght@400;500;600;700\u0026family=IBM+Plex+Sans:wght@400;500;600\u0026family=IBM+Plex+Mono:wght@400;500;600\u0026family=Unbounded:wght@600;700\u0026display=swap\",\"rel\":\"stylesheet\"}]]}],[\"$\",\"body\",null,{\"children\":[[\"$\",\"$L7\",null,{\"parallelRouterKey\":\"children\",\"segmentPath\":[\"children\"],\"error\":\"$undefined\",\"errorStyles\":\"$undefined\",\"errorScripts\":\"$undefined\",\"template\":[\"$\",\"$La\",null,{}],\"templateStyles\":\"$undefined\",\"templateScripts\":\"$undefined\",\"notFound\":[[\"$\",\"title\",null,{\"children\":\"404: This page could not be found.\"}],[\"$\",\"div\",null,{\"style\":{\"fontFamily\":\"system-ui,\\\"Segoe UI\\\",Roboto,Helvetica,Arial,sans-serif,\\\"Apple Color Emoji\\\",\\\"Segoe UI Emoji\\\"\",\"height\":\"100vh\",\"textAlign\":\"center\",\"display\":\"flex\",\"flexDirection\":\"column\",\"alignItems\":\"center\",\"justifyContent\":\"center\"},\"children\":[\"$\",\"div\",null,{\"children\":[[\"$\",\"style\",null,{\"dangerouslySetInnerHTML\":{\"__html\":\"body{color:#000;background:#fff;margin:0}.next-error-h1{border-right:1px solid rgba(0,0,0,.3)}@media (prefers-color-scheme:dark){body{color:#fff;background:#000}.next-error-h1{border-right:1px solid rgba(255,255,255,.3)}}\"}}],[\"$\",\"h1\",null,{\"className\":\"next-error-h1\",\"style\":{\"display\":\"inline-block\",\"margin\":\"0 20px 0 0\",\"padding\":\"0 23px 0 0\",\"fontSize\":24,\"fontWeight\":500,\"verticalAlign\":\"top\",\"lineHeight\":\"49px\"},\"children\":\"404\"}],[\"$\",\"div\",null,{\"style\":{\"display\":\"inline-block\"},\"children\":[\"$\",\"h2\",null,{\"style\":{\"fontSize\":14,\"fontWeight\":400,\"lineHeight\":\"49px\",\"margin\":0},\"children\":\"This page could not be found.\"}]}]]}]}]],\"notFoundStyles\":[],\"styles\":null}],[\"$\",\"$Le\",null,{}],[[\"$\",\"$Lf\",null,{\"src\":\"https://www.googletagmanager.com/gtag/js?id=G-S0TK12MVWT\",\"strategy\":\"afterInteractive\"}],[\"$\",\"$Lf\",null,{\"id\":\"ga-init\",\"strategy\":\"afterInteractive\",\"children\":\"\\n window.dataLayer = window.dataLayer || [];\\n function gtag(){dataLayer.push(arguments);}\\n gtag('js', new Date());\\n gtag('config', 'G-S0TK12MVWT');\\n \"}]]]}]]}],null],null],\"couldBeIntercepted\":false,\"initialHead\":[null,\"$L10\"],\"globalErrorComponent\":\"$11\",\"missingSlots\":\"$W12\"}]]\n"])</script><script>self.__next_f.push([1,"13:I[2716,[\"231\",\"static/chunks/231-9e11bdfe3b664aec.js\",\"4053\",\"static/chunks/app/%5Blang%5D/cve/%5Bid%5D/page-20227e05c7c03752.js\"],\"default\"]\n"])</script><script>self.__next_f.push([1,"6:[\"$\",\"div\",null,{\"className\":\"wrap\",\"children\":[[\"$\",\"script\",null,{\"type\":\"application/ld+json\",\"dangerouslySetInnerHTML\":{\"__html\":\"{\\\"@context\\\":\\\"https://schema.org\\\",\\\"@type\\\":\\\"TechArticle\\\",\\\"headline\\\":\\\"CVE-2022-1536 — automad Dashboard cross site scripting\\\",\\\"description\\\":\\\"A vulnerability has been found in automad up to 1.10.9 and classified as problematic. This vulnerability affects the Dashboard. The manipulation of the argument title with the input Home\u003c/title\u003e\u003cscript\u003ealert(\\\\\\\"home\\\\\\\")\u003c/script\u003e\u003ctitle\u003e leads to a cross s\\\",\\\"datePublished\\\":\\\"2022-04-29T13:10:12+00:00\\\",\\\"dateModified\\\":\\\"2025-04-15T14:40:54.853000+00:00\\\",\\\"inLanguage\\\":\\\"en\\\",\\\"author\\\":{\\\"@type\\\":\\\"Organization\\\",\\\"name\\\":\\\"Vexday\\\"},\\\"publisher\\\":{\\\"@type\\\":\\\"Organization\\\",\\\"name\\\":\\\"Vexday\\\",\\\"url\\\":\\\"https://vexday.io\\\"},\\\"mainEntityOfPage\\\":\\\"https://vexday.io/en/cve/CVE-2022-1536\\\",\\\"keywords\\\":\\\"CVE-2022-1536, CWE-79\\\",\\\"breadcrumb\\\":{\\\"@type\\\":\\\"BreadcrumbList\\\",\\\"itemListElement\\\":[{\\\"@type\\\":\\\"ListItem\\\",\\\"position\\\":1,\\\"name\\\":\\\"Home\\\",\\\"item\\\":\\\"https://vexday.io/en\\\"},{\\\"@type\\\":\\\"ListItem\\\",\\\"position\\\":2,\\\"name\\\":\\\"CVE-2022-1536\\\"}]}}\"}}],[\"$\",\"$Lc\",null,{\"className\":\"backlink\",\"href\":\"/en\",\"children\":\"← back\"}],[\"$\",\"article\",null,{\"className\":\"detail\",\"children\":[[\"$\",\"div\",null,{\"className\":\"cvh-head\",\"children\":[[\"$\",\"div\",null,{\"className\":\"cvh-tags\",\"children\":[[\"$\",\"span\",null,{\"className\":\"cid mono\",\"children\":\"CVE-2022-1536\"}],[\"$\",\"span\",null,{\"className\":\"cvh-tag sev-low\",\"children\":\"low\"}],false,false,false,[[\"$\",\"$Lc\",\"CWE-79\",{\"className\":\"cvh-tag t-cwe\",\"href\":\"/en/cwe/CWE-79\",\"title\":\"CWE-79 Cross Site Scripting\",\"children\":\"CWE-79\"}]]]}],[\"$\",\"h1\",null,{\"children\":\"automad Dashboard cross site scripting\"}]]}],[[\"$\",\"div\",null,{\"className\":\"cvh-verdict cvh-low\",\"children\":[[\"$\",\"div\",null,{\"className\":\"cvh-score\",\"style\":{\"color\":\"var(--muted)\"},\"children\":[8,[\"$\",\"span\",null,{\"children\":\"Vexday Risk Score\"}]]}],[\"$\",\"div\",null,{\"className\":\"cvh-div\"}],[\"$\",\"div\",null,{\"className\":\"cvh-say\",\"children\":[[\"$\",\"p\",null,{\"children\":\"No sign of exploitation. No public exploitation artifact known so far.\"}],[\"$\",\"div\",null,{\"className\":\"cvh-mini\",\"children\":[[\"$\",\"span\",null,{\"children\":[\"ssvc \",[\"$\",\"b\",null,{\"style\":{\"color\":\"var(--muted)\"},\"children\":\"Track\"}]]}],[\"$\",\"span\",null,{\"children\":[\"cvss \",[\"$\",\"b\",null,{\"children\":3.5}]]}],[\"$\",\"span\",null,{\"children\":[\"epss \",[\"$\",\"b\",null,{\"style\":{\"color\":\"var(--orange)\"},\"children\":[\"0.7\",\"%\"]}]]}]]}]]}]]}],false,[\"$\",\"div\",null,{\"className\":\"cvh-metrics\",\"children\":[[\"$\",\"div\",null,{\"className\":\"cvh-m\",\"children\":[[\"$\",\"div\",null,{\"className\":\"cvh-m-l\",\"children\":\"exploitation probability\"}],[\"$\",\"div\",null,{\"className\":\"cvh-m-v\",\"children\":[[\"$\",\"b\",null,{\"style\":{\"color\":\"var(--orange)\"},\"children\":\"0.7%\"}],[\"$\",\"span\",null,{\"children\":\"top 50% of all CVEs\"}]]}],[\"$\",\"div\",null,{\"className\":\"cvh-bar\",\"children\":[\"$\",\"span\",null,{\"style\":{\"width\":\"0.6649999999999999%\"}}]}]]}],[\"$\",\"div\",null,{\"className\":\"cvh-m\",\"children\":[[\"$\",\"div\",null,{\"className\":\"cvh-m-l\",\"children\":\"observed exploitation\"}],[\"$\",\"div\",null,{\"className\":\"cvh-m-v\",\"children\":[[\"$\",\"b\",null,{\"style\":{\"color\":\"var(--muted)\"},\"children\":\"no\"}],[\"$\",\"span\",null,{\"children\":\"no source reports it\"}]]}],[\"$\",\"div\",null,{\"className\":\"cvh-m-f\",\"children\":[false,false]}]]}]]}]],false,false,false,null,null,[\"$\",\"div\",null,{\"className\":\"desc\",\"children\":\"A vulnerability has been found in automad up to 1.10.9 and classified as problematic. This vulnerability affects the Dashboard. The manipulation of the argument title with the input Home\u003c/title\u003e\u003cscript\u003ealert(\\\"home\\\")\u003c/script\u003e\u003ctitle\u003e leads to a cross site scripting. The attack can be initiated remotely but requires an authentication. The exploit details have disclosed to the public and may be used.\"}],[\"$\",\"div\",null,{\"className\":\"vecbox\",\"children\":\"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N\"}],[\"$\",\"div\",null,{\"className\":\"block26\",\"children\":[[\"$\",\"div\",null,{\"className\":\"ph\",\"children\":\"Affected products\"}],[[\"$\",\"$Lc\",\"0\",{\"className\":\"pill\",\"href\":\"/en/vendor/unspecified\",\"style\":{\"marginRight\":8,\"display\":\"inline-block\"},\"children\":\"unspecified · automad\"}]]]}],false,false,[\"$\",\"$L13\",null,{\"lang\":\"en\",\"ctx\":\"cve\"}],[\"$\",\"div\",null,{\"className\":\"block26 reflist\",\"children\":[[\"$\",\"div\",null,{\"className\":\"ph\",\"children\":\"References\"}],[[\"$\",\"a\",\"0\",{\"href\":\"https://github.com/xiahao90/CVEproject/blob/main/xiahao.webray.com.cn/automad%3C%3D1.10.9%20Stored%20Cross-Site%20Scripting%28XSS%29.md\",\"target\":\"_blank\",\"rel\":\"noopener noreferrer nofollow\",\"children\":\"https://github.com/xiahao90/CVEproject/blob/main/xiahao.webray.com.cn/automad%3C%3D1.10.9%20Stored%20Cross-Site%20Scripting%28XSS%29.md\"}],[\"$\",\"a\",\"1\",{\"href\":\"https://vuldb.com/?id.198706\",\"target\":\"_blank\",\"rel\":\"noopener noreferrer nofollow\",\"children\":\"https://vuldb.com/?id.198706\"}]]]}]]}]]}]\n"])</script><script>self.__next_f.push([1,"10:[[\"$\",\"meta\",\"0\",{\"name\":\"viewport\",\"content\":\"width=device-width, initial-scale=1, viewport-fit=cover\"}],[\"$\",\"meta\",\"1\",{\"charSet\":\"utf-8\"}],[\"$\",\"title\",\"2\",{\"children\":\"CVE-2022-1536 — LOW 3.5 · Vexday\"}],[\"$\",\"meta\",\"3\",{\"name\":\"description\",\"content\":\"A vulnerability has been found in automad up to 1.10.9 and classified as problematic. This vulnerability affects the Dashboard. The manipulation of the arg\"}],[\"$\",\"meta\",\"4\",{\"name\":\"robots\",\"content\":\"index, follow\"}],[\"$\",\"link\",\"5\",{\"rel\":\"canonical\",\"href\":\"https://vexday.io/en/cve/CVE-2022-1536\"}],[\"$\",\"meta\",\"6\",{\"property\":\"og:title\",\"content\":\"CVE-2022-1536 — Vexday\"}],[\"$\",\"meta\",\"7\",{\"property\":\"og:description\",\"content\":\"A vulnerability has been found in automad up to 1.10.9 and classified as problematic. This vulnerability affects the Dashboard. The manipulation of the arg\"}],[\"$\",\"meta\",\"8\",{\"property\":\"og:url\",\"content\":\"https://vexday.io/en/cve/CVE-2022-1536\"}],[\"$\",\"meta\",\"9\",{\"property\":\"og:type\",\"content\":\"article\"}],[\"$\",\"meta\",\"10\",{\"name\":\"twitter:card\",\"content\":\"summary_large_image\"}],[\"$\",\"meta\",\"11\",{\"name\":\"twitter:title\",\"content\":\"CVE-2022-1536 — Vexday\"}],[\"$\",\"meta\",\"12\",{\"name\":\"twitter:description\",\"content\":\"A vulnerability has been found in automad up to 1.10.9 and classified as problematic. This vulnerability affects the Dashboard. The manipulation of the arg\"}],[\"$\",\"meta\",\"13\",{\"name\":\"twitter:image\",\"content\":\"https://vexday.io/og.png\"}],[\"$\",\"link\",\"14\",{\"rel\":\"icon\",\"href\":\"/favicon.ico\",\"type\":\"image/x-icon\",\"sizes\":\"16x16\"}],[\"$\",\"link\",\"15\",{\"rel\":\"icon\",\"href\":\"/icon.png?c9c65b69189b9a32\",\"type\":\"image/png\",\"sizes\":\"512x512\"}],[\"$\",\"link\",\"16\",{\"rel\":\"apple-touch-icon\",\"href\":\"/apple-icon.png?9705e17a98c6b822\",\"type\":\"image/png\",\"sizes\":\"180x180\"}]]\n5:null\n"])</script></body></html>