leads to a cross s","datePublished":"2022-04-29T13:10:12+00:00","dateModified":"2025-04-15T14:40:54.853000+00:00","inLanguage":"pt","author":{"@type":"Organization","name":"Vexday"},"publisher":{"@type":"Organization","name":"Vexday","url":"https://vexday.io"},"mainEntityOfPage":"https://vexday.io/pt/cve/CVE-2022-1536","keywords":"CVE-2022-1536, CWE-79","breadcrumb":{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Início","item":"https://vexday.io/pt"},{"@type":"ListItem","position":2,"name":"CVE-2022-1536"}]}}</script><a class="backlink" href="/pt">← voltar</a><article class="detail"><div class="cvh-head"><div class="cvh-tags"><span class="cid mono">CVE-2022-1536</span><span class="cvh-tag sev-low">low</span><a class="cvh-tag t-cwe" title="CWE-79 Cross Site Scripting" href="/pt/cwe/CWE-79">CWE-79</a></div><h1>automad Dashboard cross site scripting</h1></div><div class="cvh-verdict cvh-low"><div class="cvh-score" style="color:var(--muted)">8<span>Vexday Risk Score</span></div><div class="cvh-div"></div><div class="cvh-say"><p>Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.</p><div class="cvh-mini"><span>ssvc <b style="color:var(--muted)">Track</b></span><span>cvss <b>3.5</b></span><span>epss <b style="color:var(--orange)">0.7<!-- -->%</b></span></div></div></div><div class="cvh-metrics"><div class="cvh-m"><div class="cvh-m-l">probabilidade de exploração</div><div class="cvh-m-v"><b style="color:var(--orange)">0.7%</b><span>top 50% das CVEs</span></div><div class="cvh-bar"><span style="width:0.6649999999999999%"></span></div></div><div class="cvh-m"><div class="cvh-m-l">exploração observada</div><div class="cvh-m-v"><b style="color:var(--muted)">não</b><span>nenhuma fonte reporta</span></div><div class="cvh-m-f"></div></div></div><div class="desc">A vulnerability has been found in automad up to 1.10.9 and classified as problematic. This vulnerability affects the Dashboard. The manipulation of the argument title with the input Home</title><script>alert("home")</script><title> leads to a cross site scripting. The attack can be initiated remotely but requires an authentication. The exploit details have disclosed to the public and may be used.</div><div class="vecbox">CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N</div><div class="block26"><div class="ph">Produtos afetados</div><a class="pill" style="margin-right:8px;display:inline-block" href="/pt/vendor/unspecified">unspecified · automad</a></div><div class="block26 reflist"><div class="ph">Referências</div><a href="https://github.com/xiahao90/CVEproject/blob/main/xiahao.webray.com.cn/automad%3C%3D1.10.9%20Stored%20Cross-Site%20Scripting%28XSS%29.md" target="_blank" rel="noopener noreferrer nofollow">https://github.com/xiahao90/CVEproject/blob/main/xiahao.webray.com.cn/automad%3C%3D1.10.9%20Stored%20Cross-Site%20Scripting%28XSS%29.md</a><a href="https://vuldb.com/?id.198706" target="_blank" rel="noopener noreferrer nofollow">https://vuldb.com/?id.198706</a></div></article></div></main><footer><div class="wrap"><nav class="fnav"><a data-ga="vexgraph_open" data-ga-src="footer" href="/pt/vexgraph">VexGraph</a><a data-ga="live_open" data-ga-src="footer" href="/pt/live">Ao vivo</a><a data-ga="boletim_open" data-ga-src="footer" href="/pt/boletim">Boletim</a><a href="/pt/panorama">Panorama</a><a href="/pt/search">CVEs</a><a href="/pt/tech">Exposição por tecnologia</a><a href="/pt/vendors">Tecnologias</a><a href="/pt/cwes">Tipos de falha</a><a data-ga="placar_open" data-ga-src="footer" href="/pt/placar">Placar</a><a data-ga="replay_open" data-ga-src="footer" href="/pt/replay">Replay</a><a data-ga="api_docs_open" data-ga-src="footer" href="/pt/api">API</a><a data-ga="feeds_open" data-ga-src="footer" href="/pt/feeds">RSS</a><a href="/pt/privacidade">Privacidade</a></nav><div class="nvd">Vexday · um projeto <a href="https://truehacking.ai" data-ga="truehacking_cta" data-ga-location="footer" data-ga-dest="agent">TrueHacking</a>.</div></div></footer><script src="/_next/static/chunks/webpack-3cba8b0ee4f205f3.js" async=""></script><script>(self.__next_f=self.__next_f||[]).push([0]);self.__next_f.push([2,null])</script><script>self.__next_f.push([1,"1:HL[\"/_next/static/css/c36d54f802269755.css\",\"style\"]\n2:HL[\"/_next/static/css/03d82a0db5c8122c.css\",\"style\"]\n3:HL[\"/_next/static/css/55e767eb5e3cdc20.css\",\"style\"]\n"])</script><script>self.__next_f.push([1,"4:I[5751,[],\"\"]\n7:I[9275,[],\"\"]\na:I[1343,[],\"\"]\nb:I[1562,[\"231\",\"static/chunks/231-9e11bdfe3b664aec.js\",\"2986\",\"static/chunks/2986-44797c37049211bc.js\",\"1084\",\"static/chunks/app/%5Blang%5D/layout-87badba4d96c815d.js\"],\"default\"]\nc:I[231,[\"231\",\"static/chunks/231-9e11bdfe3b664aec.js\",\"4053\",\"static/chunks/app/%5Blang%5D/cve/%5Bid%5D/page-20227e05c7c03752.js\"],\"\"]\nd:I[3818,[\"231\",\"static/chunks/231-9e11bdfe3b664aec.js\",\"2986\",\"static/chunks/2986-44797c37049211bc.js\",\"1084\",\"static/chunks/app/%5Blang%5D/layout-87badba4d96c815d.js\"],\"default\"]\ne:I[7263,[\"3185\",\"static/chunks/app/layout-ec087375a8b9afad.js\"],\"default\"]\nf:I[4080,[\"3185\",\"static/chunks/app/layout-ec087375a8b9afad.js\"],\"\"]\n11:I[6130,[],\"\"]\n8:[\"lang\",\"pt\",\"d\"]\n9:[\"id\",\"CVE-2022-1536\",\"d\"]\n12:[]\n"])</script><script>self.__next_f.push([1,"0:[[[\"$\",\"link\",\"0\",{\"rel\":\"stylesheet\",\"href\":\"/_next/static/css/c36d54f802269755.css\",\"precedence\":\"next\",\"crossOrigin\":\"$undefined\"}],[\"$\",\"link\",\"1\",{\"rel\":\"stylesheet\",\"href\":\"/_next/static/css/03d82a0db5c8122c.css\",\"precedence\":\"next\",\"crossOrigin\":\"$undefined\"}],[\"$\",\"link\",\"2\",{\"rel\":\"stylesheet\",\"href\":\"/_next/static/css/55e767eb5e3cdc20.css\",\"precedence\":\"next\",\"crossOrigin\":\"$undefined\"}]],[\"$\",\"$L4\",null,{\"buildId\":\"5UfyujLKVtXJyFk-ZelQB\",\"assetPrefix\":\"\",\"initialCanonicalUrl\":\"/pt/cve/CVE-2022-1536\",\"initialTree\":[\"\",{\"children\":[[\"lang\",\"pt\",\"d\"],{\"children\":[\"cve\",{\"children\":[[\"id\",\"CVE-2022-1536\",\"d\"],{\"children\":[\"__PAGE__\",{}]}]}]}]},\"$undefined\",\"$undefined\",true],\"initialSeedData\":[\"\",{\"children\":[[\"lang\",\"pt\",\"d\"],{\"children\":[\"cve\",{\"children\":[[\"id\",\"CVE-2022-1536\",\"d\"],{\"children\":[\"__PAGE__\",{},[[\"$L5\",\"$L6\"],null],null]},[\"$\",\"$L7\",null,{\"parallelRouterKey\":\"children\",\"segmentPath\":[\"children\",\"$8\",\"children\",\"cve\",\"children\",\"$9\",\"children\"],\"error\":\"$undefined\",\"errorStyles\":\"$undefined\",\"errorScripts\":\"$undefined\",\"template\":[\"$\",\"$La\",null,{}],\"templateStyles\":\"$undefined\",\"templateScripts\":\"$undefined\",\"notFound\":\"$undefined\",\"notFoundStyles\":\"$undefined\",\"styles\":null}],null]},[\"$\",\"$L7\",null,{\"parallelRouterKey\":\"children\",\"segmentPath\":[\"children\",\"$8\",\"children\",\"cve\",\"children\"],\"error\":\"$undefined\",\"errorStyles\":\"$undefined\",\"errorScripts\":\"$undefined\",\"template\":[\"$\",\"$La\",null,{}],\"templateStyles\":\"$undefined\",\"templateScripts\":\"$undefined\",\"notFound\":\"$undefined\",\"notFoundStyles\":\"$undefined\",\"styles\":null}],null]},[[[\"$\",\"$Lb\",null,{\"lang\":\"pt\",\"searchPh\":\"buscar CVE, vendor, CWE…\",\"liveLabel\":\"Ao vivo\",\"bolLabel\":\"Boletim\",\"panoramaLabel\":\"Panorama\",\"cvesLabel\":\"CVEs\",\"threatsLabel\":\"Ameaças\",\"xtLabel\":\"Exploit Timeline\",\"toolsLabel\":\"Ferramentas\",\"intelLabel\":\"Inteligência\",\"dataLabel\":\"Dados\",\"vulnLabel\":\"Vulnerabilidades\",\"biLabel\":\"Incidentes\",\"biDesc\":\"Vazamentos com selo de confiança\",\"boardLabel\":\"Board Intelligence\",\"boardDesc\":\"O risco cibernético do dia num número que o conselho entende\",\"xpLabel\":\"Exploits\",\"xpDesc\":\"PoCs, Nuclei e Metasploit catalogados\",\"raioxLabel\":\"Raio-X\",\"iocsLabel\":\"IOCs\",\"ipcLabel\":\"Checar IP\",\"painelLabel\":\"Meu Painel\",\"vzLabel\":\"Vazamento de e-mail\",\"rcLabel\":\"Calculadora de risco de CVE\",\"rcDesc\":\"risco real de um CVE\",\"sxLabel\":\"Exposição por setor\",\"sxDesc\":\"ransomware por setor no Brasil\",\"tbLabel\":\"CVEs bomba-relógio\",\"tbDesc\":\"quase explodindo: corrija já\",\"lxLabel\":\"Verificar link encurtado\",\"lxDesc\":\"para onde vai esse link?\",\"scLabel\":\"Verificar site golpista\",\"scDesc\":\"loja falsa? verifique antes\",\"phLabel\":\"Analisar email de phishing\",\"phDesc\":\"email é golpe? cole e veja\",\"hdLabel\":\"Analisar cabeçalho de email\",\"hdDesc\":\"remetente é falso? veja o header\",\"actorsLabel\":\"Atores de Ameaça\",\"brasilLabel\":\"Ameaças ao Brasil\",\"xtDesc\":\"fila de risco\",\"threatsDesc\":\"ransomware · malware\",\"panoramaDesc\":\"observatório\",\"rxDesc\":\"sua stack vs. ataque real\",\"ipcDesc\":\"reputação de IP em segundos\",\"vzDesc\":\"monitoramento de vazamento\",\"painelDesc\":\"seu score de exposição\",\"actorsDesc\":\"524 grupos rastreados\",\"brasilDesc\":\"vítimas e grupos no país\",\"iocsDesc\":\"indicadores de ataque vivos\",\"cvesDesc\":\"361 mil vulnerabilidades\",\"bolDesc\":\"o sinal do dia, às 9h\"}],[\"$\",\"main\",null,{\"children\":[\"$\",\"$L7\",null,{\"parallelRouterKey\":\"children\",\"segmentPath\":[\"children\",\"$8\",\"children\"],\"error\":\"$undefined\",\"errorStyles\":\"$undefined\",\"errorScripts\":\"$undefined\",\"template\":[\"$\",\"$La\",null,{}],\"templateStyles\":\"$undefined\",\"templateScripts\":\"$undefined\",\"notFound\":\"$undefined\",\"notFoundStyles\":\"$undefined\",\"styles\":null}]}],[\"$\",\"footer\",null,{\"children\":[\"$\",\"div\",null,{\"className\":\"wrap\",\"children\":[[\"$\",\"nav\",null,{\"className\":\"fnav\",\"children\":[[\"$\",\"$Lc\",null,{\"href\":\"/pt/vexgraph\",\"data-ga\":\"vexgraph_open\",\"data-ga-src\":\"footer\",\"children\":\"VexGraph\"}],[\"$\",\"$Lc\",null,{\"href\":\"/pt/live\",\"data-ga\":\"live_open\",\"data-ga-src\":\"footer\",\"children\":\"Ao vivo\"}],[\"$\",\"$Lc\",null,{\"href\":\"/pt/boletim\",\"data-ga\":\"boletim_open\",\"data-ga-src\":\"footer\",\"children\":\"Boletim\"}],[\"$\",\"$Lc\",null,{\"href\":\"/pt/panorama\",\"children\":\"Panorama\"}],[\"$\",\"$Lc\",null,{\"href\":\"/pt/search\",\"children\":\"CVEs\"}],[\"$\",\"$Lc\",null,{\"href\":\"/pt/tech\",\"children\":\"Exposição por tecnologia\"}],[\"$\",\"$Lc\",null,{\"href\":\"/pt/vendors\",\"children\":\"Tecnologias\"}],[\"$\",\"$Lc\",null,{\"href\":\"/pt/cwes\",\"children\":\"Tipos de falha\"}],[\"$\",\"$Lc\",null,{\"href\":\"/pt/placar\",\"data-ga\":\"placar_open\",\"data-ga-src\":\"footer\",\"children\":\"Placar\"}],[\"$\",\"$Lc\",null,{\"href\":\"/pt/replay\",\"data-ga\":\"replay_open\",\"data-ga-src\":\"footer\",\"children\":\"Replay\"}],[\"$\",\"$Lc\",null,{\"href\":\"/pt/api\",\"data-ga\":\"api_docs_open\",\"data-ga-src\":\"footer\",\"children\":\"API\"}],[\"$\",\"$Lc\",null,{\"href\":\"/pt/feeds\",\"data-ga\":\"feeds_open\",\"data-ga-src\":\"footer\",\"children\":\"RSS\"}],[\"$\",\"$Lc\",null,{\"href\":\"/pt/privacidade\",\"children\":\"Privacidade\"}]]}],[\"$\",\"div\",null,{\"className\":\"nvd\",\"children\":[\"Vexday · um projeto \",[\"$\",\"a\",null,{\"href\":\"https://truehacking.ai\",\"data-ga\":\"truehacking_cta\",\"data-ga-location\":\"footer\",\"data-ga-dest\":\"agent\",\"children\":\"TrueHacking\"}],\".\"]}]]}]}],[\"$\",\"$Ld\",null,{\"lang\":\"pt\",\"t\":{\"msg\":\"Usamos cookies para medir o tráfego e melhorar o site. Você pode aceitar ou recusar.\",\"accept\":\"Aceitar\",\"reject\":\"Recusar\",\"more\":\"Saiba mais\"}}]],null],null]},[[\"$\",\"html\",null,{\"lang\":\"pt\",\"suppressHydrationWarning\":true,\"children\":[[\"$\",\"head\",null,{\"children\":[[\"$\",\"script\",null,{\"dangerouslySetInnerHTML\":{\"__html\":\"(function(){\\nwindow.dataLayer=window.dataLayer||[];function gtag(){dataLayer.push(arguments);}window.gtag=window.gtag||gtag;\\ngtag('consent','default',{ad_storage:'denied',ad_user_data:'denied',ad_personalization:'denied',analytics_storage:'denied',functionality_storage:'granted',security_storage:'granted',wait_for_update:500});\\ngtag('set','ads_data_redaction',true);gtag('set','url_passthrough',true);\\ntry{if(localStorage.getItem('vd-consent')==='granted'){gtag('consent','update',{ad_storage:'granted',ad_user_data:'granted',ad_personalization:'granted',analytics_storage:'granted'});}}catch(e){}\\n})();\"}}],[\"$\",\"script\",null,{\"dangerouslySetInnerHTML\":{\"__html\":\"(function(){var t;try{t=localStorage.getItem(\\\"th-theme\\\");}catch(e){}\\nif(t!==\\\"light\\\"\u0026\u0026t!==\\\"dark\\\"){t=\\\"dark\\\";}\\ndocument.documentElement.setAttribute(\\\"data-theme\\\",t);\\nwindow.toggleTheme=function(){var d=document.documentElement;var n=d.getAttribute(\\\"data-theme\\\")===\\\"dark\\\"?\\\"light\\\":\\\"dark\\\";\\nd.setAttribute(\\\"data-theme\\\",n);try{localStorage.setItem(\\\"th-theme\\\",n);}catch(e){}};\\n})();\"}}],[\"$\",\"link\",null,{\"rel\":\"preconnect\",\"href\":\"https://www.googletagmanager.com\"}],[\"$\",\"link\",null,{\"rel\":\"preconnect\",\"href\":\"https://fonts.googleapis.com\"}],[\"$\",\"link\",null,{\"rel\":\"preconnect\",\"href\":\"https://fonts.gstatic.com\",\"crossOrigin\":\"\"}],[\"$\",\"link\",null,{\"href\":\"https://fonts.googleapis.com/css2?family=Newsreader:wght@400;500;600;700\u0026family=IBM+Plex+Sans:wght@400;500;600\u0026family=IBM+Plex+Mono:wght@400;500;600\u0026family=Unbounded:wght@600;700\u0026display=swap\",\"rel\":\"stylesheet\"}]]}],[\"$\",\"body\",null,{\"children\":[[\"$\",\"$L7\",null,{\"parallelRouterKey\":\"children\",\"segmentPath\":[\"children\"],\"error\":\"$undefined\",\"errorStyles\":\"$undefined\",\"errorScripts\":\"$undefined\",\"template\":[\"$\",\"$La\",null,{}],\"templateStyles\":\"$undefined\",\"templateScripts\":\"$undefined\",\"notFound\":[[\"$\",\"title\",null,{\"children\":\"404: This page could not be found.\"}],[\"$\",\"div\",null,{\"style\":{\"fontFamily\":\"system-ui,\\\"Segoe UI\\\",Roboto,Helvetica,Arial,sans-serif,\\\"Apple Color Emoji\\\",\\\"Segoe UI Emoji\\\"\",\"height\":\"100vh\",\"textAlign\":\"center\",\"display\":\"flex\",\"flexDirection\":\"column\",\"alignItems\":\"center\",\"justifyContent\":\"center\"},\"children\":[\"$\",\"div\",null,{\"children\":[[\"$\",\"style\",null,{\"dangerouslySetInnerHTML\":{\"__html\":\"body{color:#000;background:#fff;margin:0}.next-error-h1{border-right:1px solid rgba(0,0,0,.3)}@media (prefers-color-scheme:dark){body{color:#fff;background:#000}.next-error-h1{border-right:1px solid rgba(255,255,255,.3)}}\"}}],[\"$\",\"h1\",null,{\"className\":\"next-error-h1\",\"style\":{\"display\":\"inline-block\",\"margin\":\"0 20px 0 0\",\"padding\":\"0 23px 0 0\",\"fontSize\":24,\"fontWeight\":500,\"verticalAlign\":\"top\",\"lineHeight\":\"49px\"},\"children\":\"404\"}],[\"$\",\"div\",null,{\"style\":{\"display\":\"inline-block\"},\"children\":[\"$\",\"h2\",null,{\"style\":{\"fontSize\":14,\"fontWeight\":400,\"lineHeight\":\"49px\",\"margin\":0},\"children\":\"This page could not be found.\"}]}]]}]}]],\"notFoundStyles\":[],\"styles\":null}],[\"$\",\"$Le\",null,{}],[[\"$\",\"$Lf\",null,{\"src\":\"https://www.googletagmanager.com/gtag/js?id=G-S0TK12MVWT\",\"strategy\":\"afterInteractive\"}],[\"$\",\"$Lf\",null,{\"id\":\"ga-init\",\"strategy\":\"afterInteractive\",\"children\":\"\\n window.dataLayer = window.dataLayer || [];\\n function gtag(){dataLayer.push(arguments);}\\n gtag('js', new Date());\\n gtag('config', 'G-S0TK12MVWT');\\n \"}]]]}]]}],null],null],\"couldBeIntercepted\":false,\"initialHead\":[null,\"$L10\"],\"globalErrorComponent\":\"$11\",\"missingSlots\":\"$W12\"}]]\n"])</script><script>self.__next_f.push([1,"13:I[2716,[\"231\",\"static/chunks/231-9e11bdfe3b664aec.js\",\"4053\",\"static/chunks/app/%5Blang%5D/cve/%5Bid%5D/page-20227e05c7c03752.js\"],\"default\"]\n"])</script><script>self.__next_f.push([1,"6:[\"$\",\"div\",null,{\"className\":\"wrap\",\"children\":[[\"$\",\"script\",null,{\"type\":\"application/ld+json\",\"dangerouslySetInnerHTML\":{\"__html\":\"{\\\"@context\\\":\\\"https://schema.org\\\",\\\"@type\\\":\\\"TechArticle\\\",\\\"headline\\\":\\\"CVE-2022-1536 — automad Dashboard cross site scripting\\\",\\\"description\\\":\\\"A vulnerability has been found in automad up to 1.10.9 and classified as problematic. This vulnerability affects the Dashboard. The manipulation of the argument title with the input Home\u003c/title\u003e\u003cscript\u003ealert(\\\\\\\"home\\\\\\\")\u003c/script\u003e\u003ctitle\u003e leads to a cross s\\\",\\\"datePublished\\\":\\\"2022-04-29T13:10:12+00:00\\\",\\\"dateModified\\\":\\\"2025-04-15T14:40:54.853000+00:00\\\",\\\"inLanguage\\\":\\\"pt\\\",\\\"author\\\":{\\\"@type\\\":\\\"Organization\\\",\\\"name\\\":\\\"Vexday\\\"},\\\"publisher\\\":{\\\"@type\\\":\\\"Organization\\\",\\\"name\\\":\\\"Vexday\\\",\\\"url\\\":\\\"https://vexday.io\\\"},\\\"mainEntityOfPage\\\":\\\"https://vexday.io/pt/cve/CVE-2022-1536\\\",\\\"keywords\\\":\\\"CVE-2022-1536, CWE-79\\\",\\\"breadcrumb\\\":{\\\"@type\\\":\\\"BreadcrumbList\\\",\\\"itemListElement\\\":[{\\\"@type\\\":\\\"ListItem\\\",\\\"position\\\":1,\\\"name\\\":\\\"Início\\\",\\\"item\\\":\\\"https://vexday.io/pt\\\"},{\\\"@type\\\":\\\"ListItem\\\",\\\"position\\\":2,\\\"name\\\":\\\"CVE-2022-1536\\\"}]}}\"}}],[\"$\",\"$Lc\",null,{\"className\":\"backlink\",\"href\":\"/pt\",\"children\":\"← voltar\"}],[\"$\",\"article\",null,{\"className\":\"detail\",\"children\":[[\"$\",\"div\",null,{\"className\":\"cvh-head\",\"children\":[[\"$\",\"div\",null,{\"className\":\"cvh-tags\",\"children\":[[\"$\",\"span\",null,{\"className\":\"cid mono\",\"children\":\"CVE-2022-1536\"}],[\"$\",\"span\",null,{\"className\":\"cvh-tag sev-low\",\"children\":\"low\"}],false,false,false,[[\"$\",\"$Lc\",\"CWE-79\",{\"className\":\"cvh-tag t-cwe\",\"href\":\"/pt/cwe/CWE-79\",\"title\":\"CWE-79 Cross Site Scripting\",\"children\":\"CWE-79\"}]]]}],[\"$\",\"h1\",null,{\"children\":\"automad Dashboard cross site scripting\"}]]}],[[\"$\",\"div\",null,{\"className\":\"cvh-verdict cvh-low\",\"children\":[[\"$\",\"div\",null,{\"className\":\"cvh-score\",\"style\":{\"color\":\"var(--muted)\"},\"children\":[8,[\"$\",\"span\",null,{\"children\":\"Vexday Risk Score\"}]]}],[\"$\",\"div\",null,{\"className\":\"cvh-div\"}],[\"$\",\"div\",null,{\"className\":\"cvh-say\",\"children\":[[\"$\",\"p\",null,{\"children\":\"Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.\"}],[\"$\",\"div\",null,{\"className\":\"cvh-mini\",\"children\":[[\"$\",\"span\",null,{\"children\":[\"ssvc \",[\"$\",\"b\",null,{\"style\":{\"color\":\"var(--muted)\"},\"children\":\"Track\"}]]}],[\"$\",\"span\",null,{\"children\":[\"cvss \",[\"$\",\"b\",null,{\"children\":3.5}]]}],[\"$\",\"span\",null,{\"children\":[\"epss \",[\"$\",\"b\",null,{\"style\":{\"color\":\"var(--orange)\"},\"children\":[\"0.7\",\"%\"]}]]}]]}]]}]]}],false,[\"$\",\"div\",null,{\"className\":\"cvh-metrics\",\"children\":[[\"$\",\"div\",null,{\"className\":\"cvh-m\",\"children\":[[\"$\",\"div\",null,{\"className\":\"cvh-m-l\",\"children\":\"probabilidade de exploração\"}],[\"$\",\"div\",null,{\"className\":\"cvh-m-v\",\"children\":[[\"$\",\"b\",null,{\"style\":{\"color\":\"var(--orange)\"},\"children\":\"0.7%\"}],[\"$\",\"span\",null,{\"children\":\"top 50% das CVEs\"}]]}],[\"$\",\"div\",null,{\"className\":\"cvh-bar\",\"children\":[\"$\",\"span\",null,{\"style\":{\"width\":\"0.6649999999999999%\"}}]}]]}],[\"$\",\"div\",null,{\"className\":\"cvh-m\",\"children\":[[\"$\",\"div\",null,{\"className\":\"cvh-m-l\",\"children\":\"exploração observada\"}],[\"$\",\"div\",null,{\"className\":\"cvh-m-v\",\"children\":[[\"$\",\"b\",null,{\"style\":{\"color\":\"var(--muted)\"},\"children\":\"não\"}],[\"$\",\"span\",null,{\"children\":\"nenhuma fonte reporta\"}]]}],[\"$\",\"div\",null,{\"className\":\"cvh-m-f\",\"children\":[false,false]}]]}]]}]],false,false,false,null,null,[\"$\",\"div\",null,{\"className\":\"desc\",\"children\":\"A vulnerability has been found in automad up to 1.10.9 and classified as problematic. This vulnerability affects the Dashboard. The manipulation of the argument title with the input Home\u003c/title\u003e\u003cscript\u003ealert(\\\"home\\\")\u003c/script\u003e\u003ctitle\u003e leads to a cross site scripting. The attack can be initiated remotely but requires an authentication. The exploit details have disclosed to the public and may be used.\"}],[\"$\",\"div\",null,{\"className\":\"vecbox\",\"children\":\"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N\"}],[\"$\",\"div\",null,{\"className\":\"block26\",\"children\":[[\"$\",\"div\",null,{\"className\":\"ph\",\"children\":\"Produtos afetados\"}],[[\"$\",\"$Lc\",\"0\",{\"className\":\"pill\",\"href\":\"/pt/vendor/unspecified\",\"style\":{\"marginRight\":8,\"display\":\"inline-block\"},\"children\":\"unspecified · automad\"}]]]}],false,false,[\"$\",\"$L13\",null,{\"lang\":\"pt\",\"ctx\":\"cve\"}],[\"$\",\"div\",null,{\"className\":\"block26 reflist\",\"children\":[[\"$\",\"div\",null,{\"className\":\"ph\",\"children\":\"Referências\"}],[[\"$\",\"a\",\"0\",{\"href\":\"https://github.com/xiahao90/CVEproject/blob/main/xiahao.webray.com.cn/automad%3C%3D1.10.9%20Stored%20Cross-Site%20Scripting%28XSS%29.md\",\"target\":\"_blank\",\"rel\":\"noopener noreferrer nofollow\",\"children\":\"https://github.com/xiahao90/CVEproject/blob/main/xiahao.webray.com.cn/automad%3C%3D1.10.9%20Stored%20Cross-Site%20Scripting%28XSS%29.md\"}],[\"$\",\"a\",\"1\",{\"href\":\"https://vuldb.com/?id.198706\",\"target\":\"_blank\",\"rel\":\"noopener noreferrer nofollow\",\"children\":\"https://vuldb.com/?id.198706\"}]]]}]]}]]}]\n"])</script><script>self.__next_f.push([1,"10:[[\"$\",\"meta\",\"0\",{\"name\":\"viewport\",\"content\":\"width=device-width, initial-scale=1, viewport-fit=cover\"}],[\"$\",\"meta\",\"1\",{\"charSet\":\"utf-8\"}],[\"$\",\"title\",\"2\",{\"children\":\"CVE-2022-1536 — LOW 3.5 · Vexday\"}],[\"$\",\"meta\",\"3\",{\"name\":\"description\",\"content\":\"A vulnerability has been found in automad up to 1.10.9 and classified as problematic. This vulnerability affects the Dashboard. The manipulation of the arg\"}],[\"$\",\"meta\",\"4\",{\"name\":\"robots\",\"content\":\"index, follow\"}],[\"$\",\"link\",\"5\",{\"rel\":\"canonical\",\"href\":\"https://vexday.io/pt/cve/CVE-2022-1536\"}],[\"$\",\"meta\",\"6\",{\"property\":\"og:title\",\"content\":\"CVE-2022-1536 — Vexday\"}],[\"$\",\"meta\",\"7\",{\"property\":\"og:description\",\"content\":\"A vulnerability has been found in automad up to 1.10.9 and classified as problematic. This vulnerability affects the Dashboard. The manipulation of the arg\"}],[\"$\",\"meta\",\"8\",{\"property\":\"og:url\",\"content\":\"https://vexday.io/pt/cve/CVE-2022-1536\"}],[\"$\",\"meta\",\"9\",{\"property\":\"og:type\",\"content\":\"article\"}],[\"$\",\"meta\",\"10\",{\"name\":\"twitter:card\",\"content\":\"summary_large_image\"}],[\"$\",\"meta\",\"11\",{\"name\":\"twitter:title\",\"content\":\"CVE-2022-1536 — Vexday\"}],[\"$\",\"meta\",\"12\",{\"name\":\"twitter:description\",\"content\":\"A vulnerability has been found in automad up to 1.10.9 and classified as problematic. This vulnerability affects the Dashboard. The manipulation of the arg\"}],[\"$\",\"meta\",\"13\",{\"name\":\"twitter:image\",\"content\":\"https://vexday.io/og.png\"}],[\"$\",\"link\",\"14\",{\"rel\":\"icon\",\"href\":\"/favicon.ico\",\"type\":\"image/x-icon\",\"sizes\":\"16x16\"}],[\"$\",\"link\",\"15\",{\"rel\":\"icon\",\"href\":\"/icon.png?c9c65b69189b9a32\",\"type\":\"image/png\",\"sizes\":\"512x512\"}],[\"$\",\"link\",\"16\",{\"rel\":\"apple-touch-icon\",\"href\":\"/apple-icon.png?9705e17a98c6b822\",\"type\":\"image/png\",\"sizes\":\"180x180\"}]]\n5:null\n"])</script></body></html>