VYPR
Unrated severityNVD Advisory· Published Nov 23, 2022· Updated Apr 28, 2025

CVE-2022-35501

CVE-2022-35501

Description

Stored Cross-site Scripting (XSS) exists in the Amasty Blog Pro 2.10.3 and 2.10.4 plugin for Magento 2 because of the duplicate post function.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Amasty Blog Pro for Magento 2 is vulnerable to stored XSS via the duplicate post function, allowing admin panel users to execute arbitrary JavaScript.

Vulnerability

A stored cross-site scripting (XSS) vulnerability exists in Amasty Blog Pro versions 2.10.3 and 2.10.4 for Magento 2 [2]. The vulnerability resides in the blog post creation functionality, specifically in the title field of the POST /admin/amasty_blog/posts/save/key/{some_key}/ endpoint [2]. When an administrator duplicates an existing blog post, the data.title field is used without proper sanitization, causing JavaScript code previously injected into the title to execute [2].

Exploitation

An attacker with administrative access to the Magento admin panel can create or modify a blog post with malicious JavaScript code in the title field [2]. When another administrator uses the duplicate post function, the injected script executes in the context of the admin panel [2]. No special network position or additional user interaction beyond the standard duplicate action is required [2].

Impact

Successful exploitation results in stored cross-site scripting (XSS) in the admin panel [2]. The attacker can execute arbitrary JavaScript in the victim administrator's browser, potentially leading to session hijacking, defacement, or unauthorized actions within the Magento backend [2].

Mitigation

The vulnerability is fixed in Amasty Blog Pro version 2.10.5 or newer [2]. Users should update the plugin to the latest version from the official Amasty marketplace or website [1]—[2]. No workarounds are documented in the available references [2].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.