A vulnerability, which was classified as problematic, has been found in European Environment Agency eionet.contreg. This issue affects some unknown processing. The manipulation of the argument searchTag/resourceUri leads to cross site scripting. The attack may be initiated remotely. Upgrading to version 2022-06-27T0948 is able to address this issue. The name of the patch is a120c2153e263e62c4db34a06ab96a9f1c6bccb6. It is recommended to upgrade the affected component. The identifier VDB-215885 was assigned to this vulnerability.
{
"cna_assigner": "VulDB",
"cwe_ids": [
"CWE-707"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/4xxx/CVE-2022-4513.json"
}{
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "2022-06-27t0948"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
],
"cpe": "cpe:2.3:a:eea:eionet_content_registry:*:*:*:*:*:*:*:*"
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-4513.json"
[
{
"target": {
"function": "setUri",
"file": "src/main/java/eionet/cr/web/action/factsheet/FactsheetActionBean.java"
},
"deprecated": false,
"source": "https://github.com/eea/eionet.contreg/commit/a120c2153e263e62c4db34a06ab96a9f1c6bccb6",
"id": "CVE-2022-4513-3ddb2cb2",
"signature_version": "v1",
"digest": {
"length": 61.0,
"function_hash": "291766690054689174007335976283353075022"
},
"signature_type": "Function"
},
{
"target": {
"file": "src/main/java/eionet/cr/web/action/factsheet/FactsheetActionBean.java"
},
"deprecated": false,
"source": "https://github.com/eea/eionet.contreg/commit/a120c2153e263e62c4db34a06ab96a9f1c6bccb6",
"id": "CVE-2022-4513-77ed2ea6",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"109716919426651240874763354902061270573",
"50971795767043370246865493425822085841",
"43705636024550604102539654960742358331",
"115573468973361860569008290543740021383"
]
},
"signature_type": "Line"
},
{
"target": {
"file": "src/main/java/eionet/cr/web/action/TagSearchActionBean.java"
},
"deprecated": false,
"source": "https://github.com/eea/eionet.contreg/commit/a120c2153e263e62c4db34a06ab96a9f1c6bccb6",
"id": "CVE-2022-4513-7a450272",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"44009963968453302676748712366949947276",
"331551094413578595634944611216908208772",
"201387197250488008082750346311107453299",
"72858227104987213436395399215477680001",
"40829780042211735530104363448623988551",
"288130195056198940585807537526708082867",
"174456401461637494251451368174855139381",
"271310014619308501437625874547082334968"
]
},
"signature_type": "Line"
}
]
"2026-08-12T13:33:38Z"