CVE-2022-0350: Cross-site Scripting (XSS) - Stored in vanessa219/vditor
Published Mar 31, 2022
·Updated
Cross-site Scripting (XSS) - Stored in GitHub repository vanessa219/vditor prior to 3.8.13.
Affected Software
1 affected component
b3log Vditor<3.8.13
Remediation
Event History
Mar 31, 2022
CVE Published
via MITRE·03:15 PM
Data Sourced
via MITRE·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-0350?
CVE-2022-0350 is classified as a moderate severity vulnerability due to its potential for stored cross-site scripting attacks.
2
How do I fix CVE-2022-0350?
To fix CVE-2022-0350, update your Vditor software to version 3.8.13 or later.
3
What types of applications are affected by CVE-2022-0350?
CVE-2022-0350 affects applications that use the B3log Vditor library prior to version 3.8.13.
4
Can CVE-2022-0350 lead to data breaches?
Yes, CVE-2022-0350 can enable attackers to execute malicious scripts, potentially leading to data breaches.
5
Is CVE-2022-0350 a client-side or server-side vulnerability?
CVE-2022-0350 is primarily a client-side vulnerability as it involves stored cross-site scripting.