VYPR
Unrated severityNVD Advisory· Published Mar 20, 2022· Updated Aug 3, 2024

CVE-2022-26246

CVE-2022-26246

Description

TMS v2.28.0 contains a stored XSS vulnerability in the mail settings component via unsanitized input.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

TMS v2.28.0 contains a stored XSS vulnerability in the mail settings component via unsanitized input.

Vulnerability

TMS v2.28.0 contains a stored cross-site scripting (XSS) vulnerability in the /TMS/admin/setting/mail/createorupdate endpoint. The application fails to sanitize user-supplied input before storing it, allowing arbitrary JavaScript to be injected via the port parameter or other fields. The unsanitized data is passed directly to the setting method of AdminController and executed when the page is rendered [1].

Exploitation

An attacker with administrative access to the TMS application can exploit this vulnerability by navigating to the system settings page (/TMS/admin/setting), entering malicious JavaScript (e.g., ``) into the mail configuration form, and saving the changes. The injected script is stored and executed in the context of any user who views the affected settings page, including the attacker themselves [1].

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the browser of any user accessing the mail settings page. This can lead to session hijacking, defacement, or theft of sensitive data displayed on the page. The attack is remote and does not require user interaction beyond the initial save by an admin [1].

Mitigation

As of the publication date, no official patch has been released for TMS v2.28.0. Users should restrict access to the admin panel to trusted individuals and consider applying input validation and output encoding as a workaround. Monitor the vendor's repository for future updates [1].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.