CVE-2022-2015: Cross-site Scripting (XSS) - Stored in jgraph/drawio
Published Jun 8, 2022
·Updated
Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 19.0.2.
Affected Software
1 affected component
Diagrams Drawio<19.0.2
Remediation
Event History
Jun 8, 2022
CVE Published
via MITRE·08:30 AM
Data Sourced
via MITRE·08:30 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-2015?
The severity of CVE-2022-2015 is rated as medium due to its potential for stored cross-site scripting (XSS) attacks.
2
How do I fix CVE-2022-2015?
To fix CVE-2022-2015, update the Diagrams Drawio software to version 19.0.2 or later.
3
Which versions of Diagrams Drawio are affected by CVE-2022-2015?
Versions of Diagrams Drawio prior to 19.0.2 are affected by CVE-2022-2015.
4
What type of vulnerability is CVE-2022-2015?
CVE-2022-2015 is a stored cross-site scripting (XSS) vulnerability.
5
Where can I find more information about CVE-2022-2015?
Additional information about CVE-2022-2015 can be found in the GitHub repository for jgraph/drawio.