CVE-2022-3255

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-3255
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-3255.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-3255
Aliases
Published
2022-09-21T13:15:09Z
Modified
2024-05-13T21:23:22Z
Severity
  • 4.8 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

If an attacker can control a script that is executed in the victim's browser, then they can typically fully compromise that user. Amongst other things, the attacker can: Perform any action within the application that the user can perform. View any information that the user is able to view. Modify any information that the user is able to modify. Initiate interactions with other application users, including malicious attacks, that will appear to originate from the initial victim user.

References

Affected packages

Git / github.com/pimcore/pimcore

Affected ranges

Type
GIT
Repo
https://github.com/pimcore/pimcore
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed