CVE-2022-39240

MyGraph is a permission management system. Versions prior to 1.0.4 are vulnerable to a storage XSS vulnerability leading to Remote Code Execution. This issue is patched in version 1.0.4. There is no known workaround.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:mygraph_project:mygraph:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2022-09-24 02:15

Updated : 2022-09-26 16:34


NVD link : CVE-2022-39240

Mitre link : CVE-2022-39240

CVE.ORG link : CVE-2022-39240


JSON object : View

Products Affected

mygraph_project

  • mygraph
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-80

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)