Cross-Site Scripting Vulnerability in xzs by Mindskip
CVE-2022-41431
5.4MEDIUM
What is CVE-2022-41431?
The xzs application version 3.8.0 includes a cross-site scripting (XSS) vulnerability in the /admin/question/edit component. This flaw allows attackers to inject malicious scripts into the Title text field, which can then be executed in the context of the user's browser. Successful exploitation of this vulnerability could lead to unauthorized actions and compromises of user data.
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved