CVE-2022-29349: XSS
Published May 24, 2022
·Updated
kkFileView v4.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the url parameter at /controller/OnlinePreviewController.java.
Affected Software
1 affected component
keking kkFileView=4.0.0
Event History
May 24, 2022
CVE Published
via MITRE·11:21 PM
Data Sourced
via MITRE·11:21 PM
Description
Frequently Asked Questions
1
What is CVE-2022-29349?
CVE-2022-29349 is a cross-site scripting (XSS) vulnerability found in kkFileView v4.0.0.
2
How severe is CVE-2022-29349?
CVE-2022-29349 has a severity value of 6.1, which is considered medium.
3
How does CVE-2022-29349 affect kkFileView?
CVE-2022-29349 affects kkFileView v4.0.0 by exposing a cross-site scripting (XSS) vulnerability via the URL parameter in the OnlinePreviewController.java file.
4
How can I fix CVE-2022-29349 in kkFileView v4.0.0?
To fix CVE-2022-29349, it is recommended to update kkFileView to a version that includes a patch for the vulnerability.
5
Is there any reference for CVE-2022-29349?
Yes, you can find more information about CVE-2022-29349 at the following reference: https://github.com/kekingcn/kkFileView/issues/347