CVE-2022-23059

Source
https://cve.org/CVERecord?id=CVE-2022-23059
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-23059.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-23059
Aliases
Published
2022-03-29T11:15:07.503Z
Modified
2026-03-10T23:58:47.948515Z
Severity
  • 4.8 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

A Stored Cross Site Scripting (XSS) vulnerability exists in Shopizer versions 2.0 through 2.17.0 via the “Manage Images” tab, which allows an attacker to upload a SVG file containing malicious JavaScript code.

References

Affected packages

Git /

Affected ranges

Type
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6b9f1ecd303b3b724d96bd08095c1a751dcc287e

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "2.0"
            },
            {
                "last_affected": "2.17.0"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "2.0"
            },
            {
                "last_affected": "2.17.0"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-23059.json"