CVE-2022-3223: Cross-site Scripting (XSS) - Stored in jgraph/drawio
Published Sep 16, 2022
·Updated
Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 20.3.1.
Affected Software
1 affected component
Diagrams Drawio<20.3.1
Remediation
Event History
Sep 16, 2022
CVE Published
via MITRE·10:50 AM
Data Sourced
via MITRE·10:50 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-3223?
CVE-2022-3223 is classified as a medium severity vulnerability due to its potential to allow stored cross-site scripting (XSS) attacks.
2
How do I fix CVE-2022-3223?
To fix CVE-2022-3223, upgrade Draw.io to version 20.3.1 or later, where the vulnerability has been addressed.
3
What is the impact of CVE-2022-3223?
The impact of CVE-2022-3223 includes the ability for attackers to execute arbitrary scripts in the context of another user's session, compromising their data.
4
Which versions of Draw.io are affected by CVE-2022-3223?
CVE-2022-3223 affects all versions of Draw.io prior to 20.3.1.
5
Who is the vendor for CVE-2022-3223?
The vendor for CVE-2022-3223 is Diagrams, the organization maintaining the Draw.io software.