CVE-2022-4690

MEDIUM5.4EPSS 0.26%

usememos/memos vulnerable to stored cross-site scripting (XSS)

發布日:2022/12/23修改日:2024/8/21
也稱為:GHSA-c8jh-vcjh-fx2wGO-2022-1189

描述

usememos/memos is an open-source, self-hosted memo hub with knowledge management and socialization. Memos prior to 0.9.0 has a feature to upload file and display it, and by uploading a crafted SVG file, an attacker could perform a stored cross-site scripting attack with the image direct link. This was patched in version 0.9.0.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM5.4CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

參考連結(7)