CVE-2022-3355: Cross-site Scripting (XSS) - Stored in inventree/inventree
Published Sep 29, 2022
·Updated
Cross-site Scripting (XSS) - Stored in GitHub repository inventree/inventree prior to 0.8.3.
Affected Software
1 affected component
Inventree Project Inventree<0.8.3
Remediation
Event History
Sep 29, 2022
CVE Published
via MITRE·09:25 AM
Data Sourced
via MITRE·09:25 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-3355?
CVE-2022-3355 is classified as a high severity vulnerability due to its exploitation potential in stored cross-site scripting (XSS).
2
How do I fix CVE-2022-3355?
To fix CVE-2022-3355, update the Inventree software to version 0.8.3 or later.
3
Who is affected by CVE-2022-3355?
CVE-2022-3355 affects users of Inventree versions prior to 0.8.3.
4
What type of vulnerability is CVE-2022-3355?
CVE-2022-3355 is a Cross-site Scripting (XSS) vulnerability that is stored in the application.
5
What impact does CVE-2022-3355 have?
CVE-2022-3355 can allow attackers to execute malicious scripts in the context of the affected application user's session.