Cross-Site Scripting Vulnerability in xzs by Mindskip
CVE-2022-41431
5.4MEDIUM
What is CVE-2022-41431?
The xzs application version 3.8.0 includes a cross-site scripting (XSS) vulnerability in the /admin/question/edit component. This flaw allows attackers to inject malicious scripts into the Title text field, which can then be executed in the context of the user's browser. Successful exploitation of this vulnerability could lead to unauthorized actions and compromises of user data.