CVE-2022-24833

    Dashboard / Vulnerabilities / CVE-2022-24833

    CVE-2022-24833

    Published: 11 Apr 2022Last Modified: 12 Aug 2026

    Summary: Persistent Cross-site Scripting (XSS) vulnerability in PrivateBin

    Details: PrivateBin is minimalist, open source online pastebin clone where the server has zero knowledge of pasted data. In PrivateBin < v1.4.0 a cross-site scripting (XSS) vulnerability was found. The vulnerability is present in all versions from v0.21 of the project, which was at the time still called ZeroBin. The issue is caused by the fact that SVGs can contain JavaScript. This can allow an attacker to execute code, if the user opens a paste with a specifically crafted SVG attachment, and interacts with the preview image and the instance isn't protected by an appropriate content security policy. Users are advised to either upgrade to version 1.4.0 or to ensure the content security policy of their instance is set correctly.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 2dd8b94b05a2ecaab3b39f7967012cc30be9ed62

    Affected versions

    1.3.5
    1.3.4
    1.3.3
    1.3.2
    1.3.1
    1.3

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2022-24833 | CVE-DB