-

CVE-2022-32172

Zinc - Cross-Site Scripting

In Zinc, versions v0.1.9 through v0.3.1 are vulnerable to Stored Cross-Site Scripting when using the delete template functionality. When an authenticated user deletes a template with a XSS payload in the name field, the Javascript payload will be executed and allow an attacker to access the user’s credentials.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ZinclabsZinc Version >= 0.1.9 <= 0.3.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.57% 0.424
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

https://github.com/zinclabs/zinc/commit/3376c248bade163430f9347742428f0a82cd322d
Patch
Third Party Advisory
https://www.mend.io/vulnerability-database/CVE-2022-32172
Third Party Advisory