GHSA-vp22-232w-h9x8

Suggest an improvement
Source
https://github.com/advisories/GHSA-vp22-232w-h9x8
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/12/GHSA-vp22-232w-h9x8/GHSA-vp22-232w-h9x8.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-vp22-232w-h9x8
Aliases
  • CVE-2022-4348
Published
2022-12-08T09:30:30Z
Modified
2023-11-08T04:10:44.254035Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
RuoYi-Cloud Cross-site Scripting vulnerability
Details

A vulnerability was found in yproject RuoYi-Cloud. It has been rated as problematic. Affected by this issue is some unknown functionality of the component JSON Handler. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-215108. A patch for this issue is available at https://gitee.com/yproject/RuoYi-Cloud/pulls/224.

Database specific
{
    "nvd_published_at": "2022-12-08T08:15:00Z",
    "github_reviewed_at": "2022-12-12T21:59:56Z",
    "severity": "MODERATE",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-79"
    ]
}
References

Affected packages

Maven / com.ruoyi:ruoyi-common

Package

Name
com.ruoyi:ruoyi-common
View open source insights on deps.dev
Purl
pkg:maven/com.ruoyi/ruoyi-common

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
4.6.2