CVE-2022-34619: XSS
A stored cross-site scripting (XSS) vulnerability in Mealie v0.5.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Shopping Lists item names text field.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-34619?
CVE-2022-34619 is a stored cross-site scripting (XSS) vulnerability in Mealie v0.5.5 that allows attackers to execute arbitrary web scripts or HTML.
How severe is CVE-2022-34619?
CVE-2022-34619 has a severity value of 5.4, which is considered medium.
What software versions are affected by CVE-2022-34619?
Mealie v0.5.5 is affected by CVE-2022-34619.
How can an attacker exploit CVE-2022-34619?
An attacker can exploit CVE-2022-34619 by injecting a crafted payload into the Shopping Lists item names text field, resulting in the execution of arbitrary web scripts or HTML.
Are there any references or resources available for CVE-2022-34619?
Yes, you can find more information about CVE-2022-34619 in the CWE database (CWE-79) as well as in the Mealie v0.5.6 changelog and a blog post by GainSec.