Vulnerability CVE-2022-41442


Published: 2022-10-07   Modified: 2022-10-08

Description:
PicUploader v2.6.3 was discovered to contain cross-site scripting (XSS) vulnerability via the setStorageParams function in SettingController.php.

 References:
https://github.com/xiebruce/PicUploader/commit/2b0411bddb7942e0ace136a82d4ccde0fe66f263
https://github.com/xiebruce/PicUploader/issues/80

Copyright 2026, cxsecurity.com

 

Back to Top