Description
In Recipes, versions 0.17.0 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in the ‘Name’ field of Keyword, Food and Unit components. When a victim accesses the Keyword/Food/Unit endpoints, the XSS payload will trigger. A low privileged attacker will have the victim's API key and can lead to admin's account takeover.
No analysis available yet.
Remediation
Vendor Solution
Update version to 1.2.6 or later
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-28181 | In Recipes, versions 0.17.0 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in the ‘Name’ field of Keyword, Food and Unit components. When a victim accesses the Keyword/Food/Unit endpoints, the XSS payload will trigger. A low privileged attacker will have the victim's API key and can lead to admin's account takeover. |
References
History
No history.
Status: PUBLISHED
Assigner: Mend
Published:
Updated: 2024-09-16T18:55:57.596Z
Reserved: 2022-01-10T00:00:00.000Z
Link: CVE-2022-23074
No data.
Status : Modified
Published: 2022-06-21T10:15:08.343
Modified: 2024-11-21T06:47:55.863
Link: CVE-2022-23074
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD