CVE-2022-42225: XSS
Published May 24, 2023
·Updated
Jumpserver 2.10.0 <= version <= 2.26.0 contains multiple stored XSS vulnerabilities because of improper filtering of user input, which can execute any javascript under admin's permission.
Affected Software
1 affected component
FIT2CLOUD Lina>=2.10.0<=2.26.0
Remediation
Patch Available
Event History
May 24, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this Jumpserver vulnerability?
The vulnerability ID of this Jumpserver vulnerability is CVE-2022-42225.
2
What is the severity level of CVE-2022-42225?
The severity level of CVE-2022-42225 is medium.
3
What is the description of CVE-2022-42225?
CVE-2022-42225 is a stored XSS vulnerabilities in Jumpserver 2.10.0 to 2.26.0 due to improper filtering of user input, allowing execution of arbitrary JavaScript under the admin's permission.
4
Which version of Jumpserver is affected by CVE-2022-42225?
Jumpserver versions 2.10.0 to 2.26.0 are affected by CVE-2022-42225.
5
How can the stored XSS vulnerabilities in Jumpserver be exploited?
The stored XSS vulnerabilities in Jumpserver can be exploited by injecting malicious JavaScript code into user input fields.