CVE-2022-45004: XSS
Published Mar 22, 2023
·Updated
Gophish through 0.12.1 was discovered to contain a cross-site scripting (XSS) vulnerability via a crafted landing page.
Affected Software
1 affected component
Getgophish Gophish<=0.12.1
Event History
Mar 22, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-45004?
CVE-2022-45004 has been classified as a moderate severity cross-site scripting vulnerability.
2
How do I fix CVE-2022-45004?
To fix CVE-2022-45004, update Gophish to a version beyond 0.12.1 which contains the necessary security patches.
3
What does CVE-2022-45004 affect?
CVE-2022-45004 affects the Gophish software up to version 0.12.1, allowing for cross-site scripting attacks via crafted landing pages.
4
Who is impacted by CVE-2022-45004?
Users of Gophish versions prior to 0.12.1 are impacted by CVE-2022-45004 and should take action to secure their applications.
5
What type of vulnerability is CVE-2022-45004?
CVE-2022-45004 is a cross-site scripting (XSS) vulnerability that can be exploited through malicious landing pages.