Stored Cross-Site Scripting in SHIRASAGI by SS Project
CVE-2022-43499

5.4MEDIUM

Key Information:

Status
Vendor
CVE Published:
5 December 2022

What is CVE-2022-43499?

A stored cross-site scripting vulnerability exists in SHIRASAGI versions prior to v1.16.2. This flaw allows a remote authenticated attacker with administrative privileges to inject arbitrary scripts into the system. When executed, these scripts can compromise the security of the affected application, leading to potential data theft, session hijacking, or further exploitation of the application. It is crucial for users of SHIRASAGI to upgrade to version 1.16.2 or later to mitigate this risk.

Affected Version(s)

SHIRASAGI versions prior to v1.16.2

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.