CVE-2022-4740: kkFileView picturesPreview setWatermarkAttribute cross site scripting
Published Dec 25, 2022
·Updated
A vulnerability, which was classified as problematic, has been found in kkFileView. Affected by this issue is the function setWatermarkAttribute of the file /picturesPreview. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-216776.
Affected Software
1 affected component
keking kkFileView
Event History
Dec 25, 2022
CVE Published
via MITRE·07:33 PM
Data Sourced
via MITRE·07:33 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-4740.
2
What is the severity of CVE-2022-4740?
CVE-2022-4740 has a severity of 6.1 (medium).
3
Who is affected by the vulnerability?
The vulnerability affects users of kkFileView.
4
What is the affected function of the vulnerability?
The affected function of the vulnerability is setWatermarkAttribute in the file /picturesPreview.
5
What is the impact of the vulnerability?
The vulnerability allows for remote cross-site scripting attacks.