CVE-2022-23077: Habitica - DOM XSS in login page
Published Jun 22, 2022
·Updated
In habitica versions v4.119.0 through v4.232.2 are vulnerable to DOM XSS via the login page.
Affected Software
1 affected component
habitica habitica>=4.119.0<4.233.0
Remediation
Information
Update version to v4.233.0 or later
Event History
Jun 22, 2022
CVE Published
via MITRE·11:30 AM
Data Sourced
via MITRE·11:30 AM
RemedyDescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-23077?
The severity of CVE-2022-23077 is classified as a medium risk due to potential exploitation through DOM XSS.
2
How do I fix CVE-2022-23077?
To fix CVE-2022-23077, update Habitica to version 4.233.0 or later.
3
What versions of Habitica are affected by CVE-2022-23077?
Habitica versions v4.119.0 through v4.232.2 are vulnerable to CVE-2022-23077.
4
What kind of vulnerability is CVE-2022-23077?
CVE-2022-23077 is a DOM based Cross-Site Scripting (XSS) vulnerability.
5
Can CVE-2022-23077 be exploited remotely?
Yes, CVE-2022-23077 can be exploited remotely by attackers through the login page.