CVE-2022-46391
published 2022-12-04CVE-2022-46391: AWStats 7.x through 7.8 allows XSS in the hostinfo plugin due to printing a response from Net::XWhois without proper checks.
PriorityP425medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.66%
47.2th percentile
AWStats 7.x through 7.8 allows XSS in the hostinfo plugin due to printing a response from Net::XWhois without proper checks.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| awstats | awstats | >= 0 < 7.8-2+deb11u1 | 7.8-2+deb11u1 |
| awstats | awstats | >= 0 < 7.8-3 | 7.8-3 |
| awstats | awstats | >= 0 < 7.8-3 | 7.8-3 |
| awstats | awstats | >= 0 < 7.8-3 | 7.8-3 |
| awstats | awstats | 7.0 – 7.8 | — |
| debian | awstats | < awstats 7.8-3 (bookworm) | awstats 7.8-3 (bookworm) |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
osv6.1MEDIUM
vendor_debian6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2022-46391: AWStats 7
osv·2022-12-04·CVSS 6.1
CVE-2022-46391 [MEDIUM] CVE-2022-46391: AWStats 7
AWStats 7.x through 7.8 allows XSS in the hostinfo plugin due to printing a response from Net::XWhois without proper checks.
GHSA
GHSA-j6xf-hwqw-qjg4: AWStats 7
ghsa_unreviewed·2022-12-04
CVE-2022-46391 [MEDIUM] CWE-79 GHSA-j6xf-hwqw-qjg4: AWStats 7
AWStats 7.x through 7.8 allows XSS in the hostinfo plugin due to printing a response from Net::XWhois without proper checks.
Ubuntu
AWStats vulnerability
vendor_ubuntu·2023-02-28
CVE-2022-46391 AWStats vulnerability
Title: AWStats vulnerability
Summary: AWStats could allow cross-site scripting (XSS) attacks.
It was discovered that AWStats did not properly sanitize the content of
whois responses in the hostinfo plugin. An attacker could possibly use
this issue to conduct cross-site scripting (XSS) attacks.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2022-46391: awstats - AWStats 7.x through 7.8 allows XSS in the hostinfo plugin due to printing a resp...
vendor_debian·2022·CVSS 6.1
CVE-2022-46391 [MEDIUM] CVE-2022-46391: awstats - AWStats 7.x through 7.8 allows XSS in the hostinfo plugin due to printing a resp...
AWStats 7.x through 7.8 allows XSS in the hostinfo plugin due to printing a response from Net::XWhois without proper checks.
Scope: local
bookworm: resolved (fixed in 7.8-3)
bullseye: resolved (fixed in 7.8-2+deb11u1)
forky: resolved (fixed in 7.8-3)
sid: resolved (fixed in 7.8-3)
trixie: resolved (fixed in 7.8-3)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/eldy/AWStats/pull/226https://lists.debian.org/debian-lts-announce/2022/12/msg00010.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GRFYH4DE3COMI3LJCOQQXA4FWOABU6Z2/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MYUZIFVB4N3NK4WGNHRNXZKJITCJBJX4/https://github.com/eldy/AWStats/pull/226https://lists.debian.org/debian-lts-announce/2022/12/msg00010.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GRFYH4DE3COMI3LJCOQQXA4FWOABU6Z2/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MYUZIFVB4N3NK4WGNHRNXZKJITCJBJX4/
2022-12-04
Published