CVE-2022-1730: Cross-site Scripting (XSS) - Stored in jgraph/drawio
Published May 19, 2022
·Updated
Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 18.0.4.
Affected Software
1 affected component
Diagrams Drawio<18.0.4
Remediation
Event History
May 19, 2022
CVE Published
via MITRE·01:55 PM
Data Sourced
via MITRE·01:55 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-1730?
The severity of CVE-2022-1730 is medium.
2
What is the affected software for CVE-2022-1730?
The affected software for CVE-2022-1730 is Diagrams Drawio prior to version 18.0.4.
3
How can I fix CVE-2022-1730?
To fix CVE-2022-1730, it is recommended to update to version 18.0.4 or later of Diagrams Drawio.
4
What is Cross-Site Scripting (XSS)?
Cross-Site Scripting (XSS) is a type of security vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.
5
What is the CWE number for CVE-2022-1730?
The CWE number for CVE-2022-1730 is CWE-79.