CVE-2022-32177

    Dashboard / Vulnerabilities / CVE-2022-32177

    CVE-2022-32177

    Published: 14 Oct 2022Last Modified: 12 Aug 2026

    Summary: Gin-vue-admin - Unrestricted File Upload

    Details: In "Gin-Vue-Admin", versions v2.5.1 through v2.5.3beta are vulnerable to Unrestricted File Upload that leads to execution of javascript code, through the 'Normal Upload' functionality to the Media Library. When an admin user views the uploaded file, a low privilege attacker will get access to the admin’s cookie leading to account takeover.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 076e1092f0daff63f64bf38354a8f24ac6e67a4e
    Fixed -None

    Affected versions

    2.5.3-beta

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2022-32177 | CVE-DB