Cross-Site Scripting Vulnerability in StackStorm Web UI by StackStorm
CVE-2022-43706
5.4MEDIUM
What is CVE-2022-43706?
The StackStorm Web UI has a vulnerability that allows users with write access to pack rules to carry out cross-site scripting (XSS) attacks. This allows such users to inject arbitrary scripts or HTML that could be executed in the web interface for other logged-in users, potentially compromising user sessions and sensitive data. It is essential for organizations using StackStorm versions before 3.8.0 to upgrade to mitigate these risks.
