PT-2022-25476 · Bookstack · Bookstack

Kenichi Okuno

·

Published

2022-10-24

·

Updated

2022-10-24

·

CVE-2022-40690

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions BookStack versions prior to v22.09
Description A cross-site scripting issue allows a remote authenticated attacker to inject an arbitrary script.
Recommendations For versions prior to v22.09, update to version v22.09 or later to resolve the issue.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-40690

Affected Products

Bookstack