CVE-2022-0877
Cross-site Scripting in BookStack
5.4
MEDIUM
CVSS 3.1
EPSS 0.77%
Description
Iframe tags don't have a sandbox attribute, this makes an attacker able to execute malicious javascript via an iframe and perform phishing attacks. The sandbox attribute will block script execution and prevents the content to navigate its top-level browsing context which will stop this type of attack.
How to fix CVE-2022-0877
To remediate CVE-2022-0877, upgrade the affected package to a fixed version below.
- —upgrade to 22.02.3 or later
Is CVE-2022-0877 being exploited?
Low — EPSS is 0.8%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 22.02.3
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.4 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |