CVE-2022-32171
06.10.2022, 18:16
In Zinc, versions v0.1.9 through v0.3.1 are vulnerable to Stored Cross-Site Scripting when using the delete user functionality. When an authenticated user deletes a user having a XSS payload in the user id field, the javascript payload will be executed and allow an attacker to access the users credentials.
Vendor | Product | Version |
---|---|---|
zinclabs | zinc | 0.1.9 ≤ 𝑥 ≤ 0.3.1 |
𝑥
= Vulnerable software versions