VulnerabilityModified
CVE-2022-32172
In Zinc, versions v0.1.9 through v0.3.1 are vulnerable to Stored Cross-Site Scripting when using the delete template functionality.
UnscoredEPSS 0.61%
Does this matter?
Not yet scored. NVD analysis is pending; check back once CVSS and EPSS values are published.
Description
In Zinc, versions v0.1.9 through v0.3.1 are vulnerable to Stored Cross-Site Scripting when using the delete template functionality. When an authenticated user deletes a template with a XSS payload in the name field, the Javascript payload will be executed and allow an attacker to access the user’s credentials.
- CVSS
- Not yet scored
- EPSS
- 0.61% probability · 47th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- zinclabs/zinc
- Source
- vulnerabilitylab@mend.io
References
- https://github.com/zinclabs/zinc/commit/3376c248bade163430f9347742428f0a82cd322dPatch, Third Party Advisory
- https://www.mend.io/vulnerability-database/CVE-2022-32172Third Party Advisory
- https://github.com/zinclabs/zinc/commit/3376c248bade163430f9347742428f0a82cd322dPatch, Third Party Advisory
- https://www.mend.io/vulnerability-database/CVE-2022-32172Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.