First published: Fri Jul 29 2022(Updated: )
A cross-site scripting (XSS) issue in generating a collection report made it possible for malicious clients to inject JavaScript code into the static HTML file. This issue was resolved in Velociraptor 0.6.5-2.
Credit: cve@rapid7.con
Affected Software | Affected Version | How to fix |
---|---|---|
Rapid7 Velociraptor | <0.6.5-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-35630 is a cross-site scripting (XSS) vulnerability in the collection report generation functionality in Velociraptor.
Malicious clients can exploit CVE-2022-35630 by injecting JavaScript code into the static HTML file during the collection report generation process.
The severity of CVE-2022-35630 is medium with a CVSS score of 6.1.
Velociraptor versions up to and excluding 0.6.5-2 are affected by CVE-2022-35630.
CVE-2022-35630 was resolved in Velociraptor 0.6.5-2.