PT-2022-21135 · Zinc · Zinc

Published

2022-10-06

·

Updated

2024-08-20

·

CVE-2022-32172

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Zinc versions v0.1.9 through v0.3.1
Description The issue concerns Stored Cross-Site Scripting in Zinc when using the delete template functionality. If an authenticated user deletes a template with a XSS payload in the name field, the Javascript payload will be executed, allowing an attacker to access the user’s credentials.
Recommendations For versions v0.1.9 through v0.3.1, consider disabling the delete template functionality until a patch is available to prevent exploitation of the Stored Cross-Site Scripting issue. Restrict access to the template deletion feature to minimize the risk of credential exposure.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-32172
GHSA-7J6X-42MM-P7JM
GO-2023-1896

Affected Products

Zinc