Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2022-36432 — Cross-site Scripting (XSS) in Preview functionality in Amasty Blog Pro for Magento 2 | Kitploit
Tools/GitHubGitHub/afine-com/cve-2022-36432
Vulnerability AnalysisWeb Application ExploitationWeb SecurityPapers & ResearchLearning & Education
GitHubafine-com/cve-2022-36432

CVE-2022-36432

Cross-site Scripting (XSS) in Preview functionality in Amasty Blog Pro for Magento 2

View Repository
13 years agoNot yet reviewed
Website

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2022-36432

Cross-site Scripting (XSS) in Preview functionality in Amasty Blog Pro for Magento 2

Description

The Preview functionality in the Amasty Blog Pro 2.10.3 plugin for Magento 2 uses eval unsafely. This allows attackers to perform Cross-site Scripting attacks on admin panel users by manipulating the generated preview application response.

The vulnerability is present in blog/view/base/web/js/adminhtml/preview.js file.

In references you can find a similar issue in Magento 2 in which they fixed the problem.

Affected versions

< 2.10.5

Advisory

Update Amasty Blog Pro for Magento 2 to 2.10.5 or newer.

References

  • https://github.com/magento/magento2/issues/377
  • https://amasty.com/blog-pro-for-magento-2.html
Download Tool