CVE-2022-32177

Source
https://cve.org/CVERecord?id=CVE-2022-32177
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-32177.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-32177
Published
2022-10-14T07:00:14.339Z
Modified
2026-07-15T01:49:07.279311762Z
Severity
  • 9.0 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H CVSS Calculator
Summary
Gin-vue-admin - Unrestricted File Upload
Details

In "Gin-Vue-Admin", versions v2.5.1 through v2.5.3beta are vulnerable to Unrestricted File Upload that leads to execution of javascript code, through the 'Normal Upload' functionality to the Media Library. When an admin user views the uploaded file, a low privilege attacker will get access to the admin’s cookie leading to account takeover.

Database specific
{
    "cwe_ids": [
        "CWE-434"
    ],
    "cna_assigner": "Mend",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/32xxx/CVE-2022-32177.json"
}
References

Affected packages

Git / github.com/flipped-aurora/gin-vue-admin

Affected ranges

Type
GIT
Repo
https://github.com/flipped-aurora/gin-vue-admin
Events
Database specific
{
    "cpe": [
        "cpe:2.3:a:gin-vue-admin_project:gin-vue-admin:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:gin-vue-admin_project:gin-vue-admin:2.5.3:beta:*:*:*:*:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "2.5.1"
        },
        {
            "last_affected": "2.5.2"
        },
        {
            "introduced": "2.5.3-beta"
        },
        {
            "last_affected": "2.5.3-beta"
        }
    ],
    "source": [
        "CPE_RANGE",
        "CPE_STRING"
    ]
}

Affected versions

2.*
2.5.3-beta
v2.*
v2.5.1
v2.5.1b
v2.5.2
v2.5.3beta

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-32177.json"