CVE-2022-21948: paste: XSS on the image upload function
Published Feb 7, 2023
·Updated
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in paste allows remote attackers to place Javascript into SVG files. This issue affects: openSUSE paste paste version b57b9f87e303a3db9465776e657378e96845493b and prior versions.
Affected Software
1 affected component
openSUSE paste<2011-12-05
Remediation
Patch Available
Event History
Feb 7, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this security issue?
The vulnerability ID for this issue is CVE-2022-21948.
2
What is the severity of CVE-2022-21948?
CVE-2022-21948 has a severity rating of medium (6.1).
3
How does CVE-2022-21948 affect openSUSE paste?
CVE-2022-21948 affects openSUSE paste version b57b9f87e303a3db9465776e657378e96845493b and prior versions.
4
How can remote attackers exploit CVE-2022-21948?
Remote attackers can exploit CVE-2022-21948 by placing JavaScript into SVG files.
5
Is there a fix available for CVE-2022-21948?
The fix for CVE-2022-21948 is not specified in the provided information. Please refer to the provided reference for more information.