Cross-Site Scripting Vulnerability in Cerebrate Bookmarks Component
CVE-2022-25321

6.1MEDIUM

Key Information:

Status
Vendor
CVE Published:
18 February 2022

What is CVE-2022-25321?

Cerebrate versions up to 1.4 are susceptible to a Cross-Site Scripting (XSS) vulnerability in the bookmarks component. This flaw potentially allows remote attackers to inject arbitrary web scripts into the application, which may lead to the unauthorized disclosure of sensitive user information, session hijacking, or redirection to malicious sites. Proper validation and sanitization of user input are crucial to mitigate this vulnerability.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.