MEDIUM
Cross-site Scripting (XSS) - Stored in vanessa219/vditor
Published Mar 14, 2022
5.4
MEDIUMCVSS 3.1
EPSS 0.47%
Description
Cross-site Scripting (XSS) - Stored in GitHub repository vanessa219/vditor prior to 3.8.12.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<3.8.12
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Vanessa219 | Vanessa219/vditor | n/a |
|
No data.
No Red Hat product state for this CVE.
vditor
npm
Introduced 0 Fixed 3.8.11
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | vditor | 0 | 3.8.11 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://github.com/Vanessa219/vditor/issues/1102
- https://github.com/advisories/GHSA-pq37-4c4g-v38c Advisory
- https://github.com/vanessa219/vditor/commit/219f8a9e272aba3cbc0096a82cac776532dbb9e5 x_refsource_MISCPatchThird Party Advisory
- https://huntr.dev/bounties/fa546b57-bc15-4705-824e-9474b616f628 x_refsource_CONFIRMExploitIssue TrackingPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-0341
| Link | Providers | Tags |
|---|---|---|
| https://github.com/Vanessa219/vditor/issues/1102 | ||
| https://github.com/advisories/GHSA-pq37-4c4g-v38c | Advisory | |
| https://github.com/vanessa219/vditor/commit/219f8a9e272aba3cbc0096a82cac776532dbb9e5 | x_refsource_MISCPatchThird Party Advisory | |
| https://huntr.dev/bounties/fa546b57-bc15-4705-824e-9474b616f628 | x_refsource_CONFIRMExploitIssue TrackingPatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-0341 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner @huntrdev
Published Mar 14, 2022
Updated Aug 2, 2024
Reserved Jan 24, 2022
Link CVE-2022-0341
CISA Vulnrichment
GHSA-PQ37-4C4G-V38C Updated n/a