Cross-Site Scripting Vulnerability in BookStack by BookStack App
CVE-2022-40690

5.4MEDIUM

Key Information:

Vendor

Bookstack

Status
Vendor
CVE Published:
24 October 2022

What is CVE-2022-40690?

A cross-site scripting vulnerability exists in BookStack versions prior to v22.09, enabling remote authenticated attackers to inject arbitrary scripts. This weakness may allow a malicious user to execute unauthorized actions or steal sensitive data through a successful exploitation of user interactions.

Affected Version(s)

BookStack versions prior to v22.09

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2022-40690 : Cross-Site Scripting Vulnerability in BookStack by BookStack App