CVE-2022-4859
A vulnerability, which was classified as problematic, has been found in Joget up to 7.0.33.
Does this matter?
Lower severity and a low EPSS score (0.50%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability, which was classified as problematic, has been found in Joget up to 7.0.33. This issue affects the function submitForm of the file wflow-core/src/main/java/org/joget/plugin/enterprise/UserProfileMenu.java of the component User Profile Menu. The manipulation of the argument firstName/lastName leads to cross site scripting. The attack may be initiated remotely. Upgrading to version 7.0.34 is able to address this issue. The patch is named 9a77f508a2bf8cf661d588f37a4cc29ecaea4fc8. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-217055.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.50% probability · 41th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- joget/joget dx
- Source
- cna@vuldb.com
References
- https://github.com/jogetworkflow/jw-community/commit/9a77f508a2bf8cf661d588f37a4cc29ecaea4fc8Patch
- https://github.com/jogetworkflow/jw-community/releases/tag/7.0.34Release Notes
- https://vuldb.com/?ctiid.217055Permissions Required
- https://vuldb.com/?id.217055Third Party Advisory
- https://github.com/jogetworkflow/jw-community/commit/9a77f508a2bf8cf661d588f37a4cc29ecaea4fc8Patch
- https://github.com/jogetworkflow/jw-community/releases/tag/7.0.34Release Notes
- https://vuldb.com/?ctiid.217055Permissions Required
- https://vuldb.com/?id.217055Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.