First published: Thu May 12 2022(Updated: )
HTMLCreator release_stable_2020-07-29 was discovered to contain a cross-site scripting (XSS) vulnerability via the function _generateFilename.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
DokuWiki | =2020-07-29 | |
Fedora | =34 | |
Fedora | =35 | |
Fedora | =36 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-28919 is classified as a cross-site scripting (XSS) vulnerability, which can lead to the execution of malicious scripts in a user's browser.
To fix CVE-2022-28919, update to the latest version of Dokuwiki that addresses this vulnerability.
CVE-2022-28919 affects Dokuwiki version 2020-07-29 and Fedora versions 34, 35, and 36.
CVE-2022-28919 can be easily exploited by attackers to inject malicious scripts if proper input validation is not implemented.
If affected by CVE-2022-28919, an attacker could potentially gain unauthorized access to user sessions and data, compromising user security.