CVE-2022-0121: Cross-site Scripting in hoppscotch/hoppscotch
Published Jan 6, 2022
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hoppscotch hoppscotch/hoppscotch.This issue affects hoppscotch/hoppscotch before 2.1.1.
Affected Software
1 affected component
hoppscotch hoppscotch<=2.1.0
Remediation
Event History
Jan 6, 2022
CVE Published
via MITRE·02:30 AM
Data Sourced
via MITRE·02:30 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-0121?
CVE-2022-0121 is classified as a high severity vulnerability due to its potential to allow cross-site scripting attacks.
2
How do I fix CVE-2022-0121?
To mitigate CVE-2022-0121, upgrade to hoppscotch version 2.1.1 or later, which contains the necessary patches.
3
What types of attacks can be carried out due to CVE-2022-0121?
CVE-2022-0121 allows attackers to execute arbitrary JavaScript in users' browsers, leading to potential data theft or session hijacking.
4
Which versions of hoppscotch are affected by CVE-2022-0121?
CVE-2022-0121 affects hoppscotch versions prior to 2.1.1.
5
Is user input vulnerability the main issue with CVE-2022-0121?
Yes, CVE-2022-0121 stems from improper neutralization of user input, leading to potential cross-site scripting vulnerabilities.