CVE-2022-0970: Cross-site Scripting (XSS) - Stored in getgrav/grav
Published Mar 15, 2022
·Updated
Cross-site Scripting (XSS) - Stored in GitHub repository getgrav/grav prior to 1.7.31.
Affected Software
1 affected component
getgrav Grav<1.7.31
Remediation
Event History
Mar 15, 2022
CVE Published
via MITRE·04:40 PM
Data Sourced
via MITRE·04:40 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-0970?
CVE-2022-0970 is a Cross-site Scripting (XSS) vulnerability that was found in the GitHub repository getgrav/grav prior to version 1.7.31.
2
How does CVE-2022-0970 impact my system?
CVE-2022-0970 could allow an attacker to inject malicious scripts into the web application, potentially compromising user data and performing unauthorized actions.
3
What software versions are affected by CVE-2022-0970?
Versions of Getgrav Grav prior to 1.7.31 are affected by CVE-2022-0970.
4
How severe is CVE-2022-0970?
CVE-2022-0970 is classified as a high-severity vulnerability with a CVSS score of 5.4.
5
How can I fix CVE-2022-0970?
To fix CVE-2022-0970, update your Getgrav Grav installation to version 1.7.31 or later.