First published: Tue Mar 15 2022(Updated: )
Cross-site Scripting (XSS) - Stored in GitHub repository getgrav/grav prior to 1.7.31.
Credit: security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Getgrav Grav | <1.7.31 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-0970 is a Cross-site Scripting (XSS) vulnerability that was found in the GitHub repository getgrav/grav prior to version 1.7.31.
CVE-2022-0970 could allow an attacker to inject malicious scripts into the web application, potentially compromising user data and performing unauthorized actions.
Versions of Getgrav Grav prior to 1.7.31 are affected by CVE-2022-0970.
CVE-2022-0970 is classified as a high-severity vulnerability with a CVSS score of 5.4.
To fix CVE-2022-0970, update your Getgrav Grav installation to version 1.7.31 or later.