S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-26159 Scanner

CVE-2022-26159 scanner - Information Disclosure vulnerability in Auto-Completion plugin for Ametys CMS

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.3k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-26159
5.3
CVSS

The auto-completion plugin in Ametys CMS before 4.5.0 allows a remote unauthenticated attacker to read documents such as plugins/web/service/search/auto-completion/<domain>/en.xml (and similar pathnames for other languages), which contain all characters typed by all users, including the content of private pages. For example, a private page may contain usernames, e-mail addresses, and possibly passwords.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

The Auto-Completion plugin is a feature that is commonly used in Ametys CMS to help users search for content within the system. The plugin provides suggestions as the user types, making it easier to find the content they need. It is especially useful when users are searching for pages with long titles or complex keywords. The Auto-Completion plugin for Ametys CMS is a valuable tool for anyone who needs to navigate their CMS efficiently.

The CVE-2022-26159 vulnerability was recently detected in Ametys CMS's Auto-Completion plugin, and it is critical that all users take steps to protect their system. This vulnerability allows remote, unauthenticated attackers to access sensitive documents such as <domain>/en.xml. The compromised documents contain all the characters typed by all users, including the content of private pages. This means that usernames, email addresses, and even passwords could be exposed to attackers.

If this vulnerability is exploited, it can lead to significant damage to an organization's digital assets. Attackers could use the information gained through the vulnerability to access sensitive information belonging to users of the system. Additionally, any sensitive organizational information stored in the CMS's private pages could be at risk. This could result in identity theft, data breaches, and other cyberattacks.

Thanks to the pro features of the s4e.io platform, users can quickly and easily learn about vulnerabilities in their digital assets. With our comprehensive suite of security tools and resources, users can stay informed about the latest threats and take proactive steps to protect their digital assets. Don't let cybersecurity vulnerabilities compromise your organization's sensitive information—sign up for s4e.io today!

 

REFERENCES

Solution Advice

To protect against the CVE-2022-26159 vulnerability, users of Ametys CMS should take the following precautions:

  • Update the Auto-Completion plugin to the latest version as soon as possible.
  • Monitor system logs for suspicious activity.
  • Restrict access to sensitive pages/documents to only authorized users.
  • Ensure that all users of the CMS have strong, unique passwords.
  • Educate users on the importance of cybersecurity best practices.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.