CVE-2022-28919: XSS
Published May 12, 2022
·Updated
HTMLCreator releasestable2020-07-29 was discovered to contain a cross-site scripting (XSS) vulnerability via the function generateFilename.
Affected Software
4 affected components
DokuWiki DokuWiki=2020-07-29
Fedoraproject Fedora=34
Fedoraproject Fedora=35
Fedoraproject Fedora=36
Event History
May 12, 2022
CVE Published
via MITRE·03:43 PM
Data Sourced
via MITRE·03:43 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-28919?
CVE-2022-28919 is classified as a cross-site scripting (XSS) vulnerability, which can lead to the execution of malicious scripts in a user's browser.
2
How do I fix CVE-2022-28919?
To fix CVE-2022-28919, update to the latest version of Dokuwiki that addresses this vulnerability.
3
What software is affected by CVE-2022-28919?
CVE-2022-28919 affects Dokuwiki version 2020-07-29 and Fedora versions 34, 35, and 36.
4
Is CVE-2022-28919 easy to exploit?
CVE-2022-28919 can be easily exploited by attackers to inject malicious scripts if proper input validation is not implemented.
5
What can happen if I am affected by CVE-2022-28919?
If affected by CVE-2022-28919, an attacker could potentially gain unauthorized access to user sessions and data, compromising user security.