CVE-2022-32167: Cloudreve - Stored XSS
Cloudreve versions v1.0.0 through v3.5.3 are vulnerable to Stored Cross-Site Scripting (XSS), via the file upload functionality. A low privileged user will be able to share a file with an admin user, which could lead to privilege escalation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-32167?
The severity of CVE-2022-32167 is considered low, as it involves stored cross-site scripting (XSS) within Cloudreve.
How do I fix CVE-2022-32167?
To fix CVE-2022-32167, upgrade Cloudreve to a version later than 3.5.3 that addresses this vulnerability.
Who is affected by CVE-2022-32167?
CVE-2022-32167 affects all versions of Cloudreve from v1.0.0 through v3.5.3.
What type of attack can CVE-2022-32167 lead to?
CVE-2022-32167 can lead to stored cross-site scripting (XSS) attacks and potential privilege escalation.
How does CVE-2022-32167 exploit file uploads?
CVE-2022-32167 exploits file uploads by allowing lower-privileged users to share malicious files with admin users, triggering XSS.