5.4

CVE-2022-23065

Exploit
In Vendure versions 0.1.0-alpha.2 to 1.5.1 are affected by Stored XSS vulnerability, where an attacker having catalog permission can upload a SVG file that contains malicious JavaScript into the “Assets” tab. The uploaded file will affect administrators as well as regular users.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VendureVendure Version >= 0.1.2 <= 1.5.1
VendureVendure Version0.1.0 Updatealpha10
VendureVendure Version0.1.0 Updatealpha11
VendureVendure Version0.1.0 Updatealpha12
VendureVendure Version0.1.0 Updatealpha13
VendureVendure Version0.1.0 Updatealpha14
VendureVendure Version0.1.0 Updatealpha15
VendureVendure Version0.1.0 Updatealpha16
VendureVendure Version0.1.0 Updatealpha18
VendureVendure Version0.1.0 Updatealpha2
VendureVendure Version0.1.0 Updatealpha3
VendureVendure Version0.1.0 Updatealpha4
VendureVendure Version0.1.0 Updatealpha5
VendureVendure Version0.1.0 Updatealpha6
VendureVendure Version0.1.0 Updatealpha7
VendureVendure Version0.1.0 Updatealpha8
VendureVendure Version0.1.0 Updatealpha9
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.43
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 3.5 6.8 2.9
AV:N/AC:M/Au:S/C:N/I:P/A:N
vulnerabilitylab@mend.io 5.4 2.3 2.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.