CVE-2022-3127: Cross-site Scripting (XSS) - Stored in jgraph/drawio
Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 20.2.8.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-3127?
CVE-2022-3127 has been classified as a moderate severity vulnerability, primarily due to its potential for exploitation via stored cross-site scripting (XSS).
How do I fix CVE-2022-3127?
To fix CVE-2022-3127, update your Diagrams Drawio software to version 20.2.8 or later to mitigate the vulnerability.
What type of attack does CVE-2022-3127 allow?
CVE-2022-3127 allows for stored cross-site scripting (XSS) attacks, where malicious scripts can be executed in the context of a user's session.
Who is affected by CVE-2022-3127?
Users of Diagrams Drawio versions prior to 20.2.8 are affected by CVE-2022-3127 and are at risk of XSS attacks.
When was CVE-2022-3127 discovered?
CVE-2022-3127 was reported and disclosed in 2022, affecting versions of the Diagrams Drawio software before the release of version 20.2.8.