CVE-2022-0268: Cross-site Scripting (XSS) - Stored in getgrav/grav
Published Jan 25, 2022
·Updated
Cross-site Scripting (XSS) - Stored in Packagist getgrav/grav prior to 1.7.28.
Affected Software
1 affected component
getgrav Grav<1.7.28
Remediation
Event History
Jan 25, 2022
CVE Published
via MITRE·10:40 AM
Data Sourced
via MITRE·10:40 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-0268?
CVE-2022-0268 is a Cross-site Scripting (XSS) vulnerability that is stored in Packagist getgrav/grav prior to version 1.7.28.
2
What is the severity of CVE-2022-0268?
The severity of CVE-2022-0268 is medium with a CVSS score of 5.4.
3
How does CVE-2022-0268 affect Getgrav Grav?
CVE-2022-0268 affects Getgrav Grav versions prior to 1.7.28, allowing stored cross-site scripting (XSS) attacks.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2022-0268?
The Common Weakness Enumeration (CWE) ID for CVE-2022-0268 is CWE-79.
5
How can I fix CVE-2022-0268?
To fix CVE-2022-0268, please update Getgrav Grav to version 1.7.28 or later.