CVE-2022-42248: XSS
Published Mar 6, 2023
·Updated
QlikView 12.60.2 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the QvsViewClient functionality.
Affected Software
1 affected component
Qlik Qlikview<=12.60
Event History
Mar 6, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-42248?
CVE-2022-42248 is considered a medium severity vulnerability due to its potential for impact through stored cross-site scripting.
2
How do I fix CVE-2022-42248?
To fix CVE-2022-42248, upgrade to the latest version of QlikView that addresses this vulnerability.
3
What type of vulnerability is CVE-2022-42248?
CVE-2022-42248 is a stored cross-site scripting (XSS) vulnerability found in QlikView's QvsViewClient functionality.
4
Which versions of QlikView are affected by CVE-2022-42248?
CVE-2022-42248 affects QlikView version 12.60.2 and prior versions up to 12.60.
5
What can attackers do with CVE-2022-42248?
With CVE-2022-42248, attackers can inject malicious scripts that may lead to unauthorized actions or data compromise in the context of the user.