CVE-2022-22126

Source
https://cve.org/CVERecord?id=CVE-2022-22126
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-22126.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-22126
Published
2022-02-20T19:00:14Z
Modified
2026-08-12T03:51:27.876554453Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
Openmct XSS via the “Web Page” element
Details

Openmct versions 1.3.0 to 1.7.7 are vulnerable against stored XSS via the “Web Page” element, that allows the injection of malicious JavaScript into the ‘URL’ field. This issue affects: nasa openmct 1.7.7 version and prior versions; 1.3.0 version and later versions.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/22xxx/CVE-2022-22126.json",
    "cwe_ids": [
        "CWE-79"
    ],
    "cna_assigner": "Mend"
}
References

Affected packages

Git / github.com/nasa/openmct

Affected ranges

Type
GIT
Repo
https://github.com/nasa/openmct
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:nasa:openmct:*:*:*:*:*:*:*:*",
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "1.3.0"
        },
        {
            "last_affected": "1.7.7"
        }
    ]
}

Affected versions

1.*
1.7.7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-22126.json"