CVE-2022-30289: XSS
A stored Cross-site Scripting (XSS) vulnerability was identified in the Data Import functionality of OpenCTI through 5.2.4. An attacker can abuse the vulnerability to upload a malicious file that will then be executed by a victim when they open the file location.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-30289?
CVE-2022-30289 is classified as a medium severity stored Cross-site Scripting (XSS) vulnerability.
How do I fix CVE-2022-30289?
To fix CVE-2022-30289, you should update OpenCTI to version 5.2.5 or later.
What impact does CVE-2022-30289 have on users?
CVE-2022-30289 allows attackers to execute malicious scripts in the context of a victim's browser, potentially compromising sensitive information.
Who is affected by CVE-2022-30289?
Any users of OpenCTI versions up to and including 5.2.4 are affected by CVE-2022-30289.
How can an attacker exploit CVE-2022-30289?
An attacker can exploit CVE-2022-30289 by uploading a malicious file through the Data Import functionality that executes when accessed by the victim.