First published: Wed May 24 2023(Updated: )
Jumpserver 2.10.0 <= version <= 2.26.0 contains multiple stored XSS vulnerabilities because of improper filtering of user input, which can execute any javascript under admin's permission.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Fit2cloud Lina | >=2.10.0<=2.26.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this Jumpserver vulnerability is CVE-2022-42225.
The severity level of CVE-2022-42225 is medium.
CVE-2022-42225 is a stored XSS vulnerabilities in Jumpserver 2.10.0 to 2.26.0 due to improper filtering of user input, allowing execution of arbitrary JavaScript under the admin's permission.
Jumpserver versions 2.10.0 to 2.26.0 are affected by CVE-2022-42225.
The stored XSS vulnerabilities in Jumpserver can be exploited by injecting malicious JavaScript code into user input fields.