PT-2022-26448 · Softwarex · Softwarex

Qing Xu

·

Published

2022-10-19

·

Updated

2025-05-08

·

CVE-2022-42466

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SoftwareX versions prior to 2.0.0-M9
Description The issue allows an end-user to set the value of an editable string property of a domain object to a value that would be rendered unchanged when the value was saved. This enables the end-user to enter javascript or similar, which would be executed. The inputted strings are now properly escaped when rendered.
Recommendations For versions prior to 2.0.0-M9, update to version 2.0.0-M9 or later to ensure inputted strings are properly escaped when rendered.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-42466
GHSA-7PFC-CC9X-8P4M

Affected Products

Softwarex