First published: Mon Apr 10 2017(Updated: )
Swagger-UI before 2.2.1 has XSS via the Default field in the Definitions section.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
SmartBear Swagger UI | <2.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-5682 is classified as a high severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
To fix CVE-2016-5682, upgrade Swagger-UI to version 2.2.1 or later, which resolves the vulnerability.
CVE-2016-5682 can facilitate persistent cross-site scripting (XSS) attacks that could compromise user data.
Swagger-UI versions prior to 2.2.1 are affected by CVE-2016-5682.
The impact of CVE-2016-5682 on applications includes potential injection of malicious scripts leading to unauthorized actions on behalf of users.