CVE-2022-40440: XSS
Published Oct 11, 2022
·Updated
mxGraph v4.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the setTooltips() function.
Other sources
mxGraph v4.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the setTooltips() function.
Affected Software
2 affected components
npm/mxgraph<=4.2.2
jgraph mxGraph=4.2.2
Event History
Oct 11, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Oct 12, 2022
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeaknessAffected Software
Advisory Published
12:00 PM
Frequently Asked Questions
1
What is the severity of CVE-2022-40440?
CVE-2022-40440 is considered a critical cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2022-40440?
To remediate CVE-2022-40440, update mxGraph to version 4.2.3 or later where the vulnerability is patched.
3
What are the potential impacts of CVE-2022-40440?
Exploitation of CVE-2022-40440 can lead to unauthorized access to user data via executed scripts in the user's browser.
4
Which versions of mxGraph are affected by CVE-2022-40440?
CVE-2022-40440 affects mxGraph version 4.2.2 and prior versions.
5
Is CVE-2022-40440 a client-side or server-side vulnerability?
CVE-2022-40440 is a client-side vulnerability, specifically a cross-site scripting issue.