CVE-2022-32172
Dashboard / Vulnerabilities / CVE-2022-32172
CVE-2022-32172
Published: 6 Oct 2022Last Modified: 27 Aug 2026
Aliases:
Summary: Zinc - Cross-Site Scripting
Details: In Zinc, versions v0.1.9 through v0.3.1 are vulnerable to Stored Cross-Site Scripting when using the delete template functionality. When an authenticated user deletes a template with a XSS payload in the name field, the Javascript payload will be executed and allow an attacker to access the user’s credentials.
References: https://www.mend.io/vulnerability-database/CVE-2022-32172, https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/32xxx/CVE-2022-32172.json, https://nvd.nist.gov/vuln/detail/CVE-2022-32172, https://github.com/zinclabs/zinc/commit/3376c248bade163430f9347742428f0a82cd322d
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- 166f7c50307bf3e17279e42e280a71dee13a11fb
Affected versions
v0.1.9
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
