Cross-Site Scripting Vulnerability in mxGraph by jGraph
CVE-2022-40440

6.1MEDIUM

Key Information:

Vendor

Jgraph

Status
Vendor
CVE Published:
12 October 2022

What is CVE-2022-40440?

mxGraph v4.2.2 has been identified to have a cross-site scripting vulnerability in its setTooltips() function. This flaw can allow attackers to inject malicious scripts into the web application, potentially compromising user data and session integrity. Developers using this version should review their implementation and apply necessary security measures to mitigate risks.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.