-

CVE-2022-32172

Zinc - Cross-Site Scripting

In Zinc, versions v0.1.9 through v0.3.1 are vulnerable to Stored Cross-Site Scripting when using the delete template functionality. When an authenticated user deletes a template with a XSS payload in the name field, the Javascript payload will be executed and allow an attacker to access the user’s credentials.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zinclabs ≫ Zinc Version >= 0.1.9 <= 0.3.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.59% 0.443
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

https://github.com/zinclabs/zinc/commit/3376c248bade163430f9347742428f0a82cd322d
Patch
Third Party Advisory
https://www.mend.io/vulnerability-database/CVE-2022-32172
Third Party Advisory