CVE-2022-25869
All versions of the package angular; all versions of the package angularjs.core; all versions of the package angularjs are vulnerable to Cross-site Scripting (XSS) due to insecure page caching in the Internet Explorer browser, which allows interpolation…
Does this matter?
Lower severity and a low EPSS score (7.27%). Track it; it rarely justifies an emergency change on its own.
Description
All versions of the package angular; all versions of the package angularjs.core; all versions of the package angularjs are vulnerable to Cross-site Scripting (XSS) due to insecure page caching in the Internet Explorer browser, which allows interpolation of <textarea> elements.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 7.27% probability · 94th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- angularjs/angularjs
- Source
- report@snyk.io
References
- https://neverendingsupport.github.io/angularjs-poc-cve-2022-25869
- https://security.snyk.io/vuln/SNYK-DOTNET-ANGULARJS-10771617
- https://security.snyk.io/vuln/SNYK-DOTNET-ANGULARJSCORE-6084031
- https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-2949783
- https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBANGULAR-2949784
- https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-2949782
- https://security.snyk.io/vuln/SNYK-JS-ANGULAR-2949781
- https://glitch.com/edit/%23%21/angular-repro-textarea-xssBroken Link
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-2949783Exploit, Third Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBANGULAR-2949784Exploit, Third Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-2949782Exploit, Third Party Advisory
- https://snyk.io/vuln/SNYK-JS-ANGULAR-2949781Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.