CVE-2022-3138: Cross-site Scripting (XSS) - Generic in jgraph/drawio
Published Sep 8, 2022
·Updated
Cross-site Scripting (XSS) - Generic in GitHub repository jgraph/drawio prior to 20.3.0.
Affected Software
1 affected component
Diagrams Drawio<20.3.0
Remediation
Event History
Sep 8, 2022
CVE Published
via MITRE·09:30 AM
Data Sourced
via MITRE·09:30 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-3138?
The severity of CVE-2022-3138 is classified as medium due to its potential impact on user data through cross-site scripting.
2
How do I fix CVE-2022-3138?
To fix CVE-2022-3138, upgrade to version 20.3.0 or later of the Draw.io application.
3
What types of systems are affected by CVE-2022-3138?
CVE-2022-3138 affects all versions of Draw.io prior to 20.3.0.
4
What type of vulnerability is CVE-2022-3138?
CVE-2022-3138 is a cross-site scripting (XSS) vulnerability.
5
Can CVE-2022-3138 be exploited remotely?
Yes, CVE-2022-3138 can be exploited remotely by an attacker to execute malicious scripts in the context of a user's session.