CVE-2022-48118: XSS
Published Jan 27, 2023
·Updated
Jorani v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Acronym parameter.
Affected Software
2 affected components
Jorani Project Jorani=1.0.0
Jorani Jorani=1.0.0
Event History
Jan 27, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2022-48118?
CVE-2022-48118 is a cross-site scripting (XSS) vulnerability in Jorani v1.0 via the Acronym parameter.
2
How does the cross-site scripting (XSS) vulnerability work in Jorani v1.0?
The cross-site scripting (XSS) vulnerability in Jorani v1.0 occurs through the Acronym parameter, allowing an attacker to execute malicious scripts on a victim's browser.
3
What is the severity of CVE-2022-48118?
The severity of CVE-2022-48118 is medium with a CVSS score of 6.1.
4
Which software versions are affected by CVE-2022-48118?
Jorani v1.0.0 is affected by CVE-2022-48118.
5
How can I fix the cross-site scripting (XSS) vulnerability in Jorani v1.0?
To fix the cross-site scripting (XSS) vulnerability in Jorani v1.0, it is recommended to update to a patched version provided by the Jorani project.