CVE-2022-4866: Cross-site Scripting (XSS) - Stored in usememos/memos
Published Dec 31, 2022
·Updated
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.
Affected Software
1 affected component
usememos memos<0.9.1
Remediation
Event History
Dec 31, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-4866.
2
What is the severity of CVE-2022-4866?
The severity of CVE-2022-4866 is critical (9 out of 10).
3
What is the affected software?
The affected software is Usememos Memos prior to version 0.9.1.
4
What is the CWE ID associated with CVE-2022-4866?
The CWE ID associated with CVE-2022-4866 is CWE-79 (Cross-Site Scripting).
5
How do I fix CVE-2022-4866?
To fix CVE-2022-4866, update the Usememos Memos repository to version 0.9.1 or later.