Ametys CMS v4.4.1 contains a persistent cross-site scripting vulnerability in the link directory's input fields for external links. Attackers can inject malicious script code in link text and descriptions to execute persistent attacks that compromise user sessions and manipulate application modules.
References
| Link | Resource |
|---|---|
| https://www.ametys.org/community/en/ametys-platform/ametys-portal/overview.html | Product |
| https://www.exploit-db.com/exploits/50692 | Exploit Third Party Advisory |
| https://www.vulncheck.com/advisories/ametys-cms-cross-site-scripting-xss | Third Party Advisory |
| https://www.vulnerability-lab.com/get_content.php?id=2275 | Exploit Third Party Advisory |
| https://www.exploit-db.com/exploits/50692 | Exploit Third Party Advisory |
| https://www.vulnerability-lab.com/get_content.php?id=2275 | Exploit Third Party Advisory |
Configurations
History
02 Feb 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.1 |
30 Jan 2026, 15:22
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Ametys
Ametys ametys |
|
| CPE | cpe:2.3:a:ametys:ametys:4.4.1:*:*:*:*:*:*:* | |
| References | () https://www.ametys.org/community/en/ametys-platform/ametys-portal/overview.html - Product | |
| References | () https://www.exploit-db.com/exploits/50692 - Exploit, Third Party Advisory | |
| References | () https://www.vulncheck.com/advisories/ametys-cms-cross-site-scripting-xss - Third Party Advisory | |
| References | () https://www.vulnerability-lab.com/get_content.php?id=2275 - Exploit, Third Party Advisory |
14 Jan 2026, 20:15
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.exploit-db.com/exploits/50692 - | |
| References | () https://www.vulnerability-lab.com/get_content.php?id=2275 - |
13 Jan 2026, 23:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-13 23:15
Updated : 2026-02-02 16:16
NVD link : CVE-2022-50937
Mitre link : CVE-2022-50937
CVE.ORG link : CVE-2022-50937
JSON object : View
Products Affected
ametys
- ametys
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
