CVE-2022-0341: Cross-site Scripting (XSS) - Stored in vanessa219/vditor
Published Mar 14, 2022
·Updated
Cross-site Scripting (XSS) - Stored in GitHub repository vanessa219/vditor prior to 3.8.12.
Affected Software
1 affected component
b3log Vditor<3.8.12
Remediation
Event History
Mar 14, 2022
CVE Published
via MITRE·04:10 AM
Data Sourced
via MITRE·04:10 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-0341?
CVE-2022-0341 has been classified as a moderate severity vulnerability due to its potential for stored cross-site scripting attacks.
2
How do I fix CVE-2022-0341?
To fix CVE-2022-0341, upgrade to version 3.8.12 or later of the B3log Vditor.
3
What are the consequences of exploiting CVE-2022-0341?
Exploiting CVE-2022-0341 could allow attackers to execute malicious scripts in the context of the affected application, potentially compromising user data.
4
In which software versions is CVE-2022-0341 present?
CVE-2022-0341 is present in all versions of B3log Vditor prior to 3.8.12.
5
Who is affected by CVE-2022-0341?
Users of the B3log Vditor before version 3.8.12 are affected by CVE-2022-0341.