CVE-2022-2290: Cross-site Scripting (XSS) - Reflected in zadam/trilium
Published Jul 3, 2022
·Updated
Cross-site Scripting (XSS) - Reflected in GitHub repository zadam/trilium prior to 0.52.4, 0.53.1-beta.
Affected Software
2 affected components
Trilium Project Trilium<0.52.4
Triliumnotes Trilium<0.52.4
Remediation
Event History
Jul 3, 2022
CVE Published
via MITRE·06:05 AM
Data Sourced
via MITRE·06:05 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-2290?
CVE-2022-2290 is classified as a cross-site scripting (XSS) vulnerability, which can lead to security risks for affected users.
2
How do I fix CVE-2022-2290?
To remediate CVE-2022-2290, update Trilium to version 0.52.4 or later.
3
What software is affected by CVE-2022-2290?
CVE-2022-2290 affects Trilium versions prior to 0.52.4 and 0.53.1-beta.
4
Can CVE-2022-2290 be exploited remotely?
Yes, CVE-2022-2290 can be exploited remotely as it involves reflected cross-site scripting.
5
How can I detect if my application is vulnerable to CVE-2022-2290?
You can detect CVE-2022-2290 by reviewing application logs for unusual scripts or patterns that suggest XSS attempts.