Логотип exploitDog
bind:CVE-2022-31191
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-31191

Количество 2

Количество 2

nvd логотип

CVE-2022-31191

больше 3 лет назад

DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui is a UI component for DSpace. The JSPUI spellcheck "Did you mean" HTML escapes the data-spell attribute in the link, but not the actual displayed text. Similarly, the JSPUI autocomplete HTML does not properly escape text passed to it. Both are vulnerable to XSS. This vulnerability only impacts the JSPUI. Users are advised to upgrade. There are no known workarounds for this issue.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-c558-5gfm-p2r8

больше 3 лет назад

JSPUI spellcheck and autocomplete tools vulnerable to Cross Site Scripting

CVSS3: 7.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-31191

DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui is a UI component for DSpace. The JSPUI spellcheck "Did you mean" HTML escapes the data-spell attribute in the link, but not the actual displayed text. Similarly, the JSPUI autocomplete HTML does not properly escape text passed to it. Both are vulnerable to XSS. This vulnerability only impacts the JSPUI. Users are advised to upgrade. There are no known workarounds for this issue.

CVSS3: 7.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-c558-5gfm-p2r8

JSPUI spellcheck and autocomplete tools vulnerable to Cross Site Scripting

CVSS3: 7.1
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу