PT-2022-27120 · Unknown · Nuxt/Framework

Published

2022-12-11

·

Updated

2022-12-13

·

CVE-2022-4414

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions nuxt/framework versions prior to 3.0.0-rc.13
Description The issue is related to Cross-site Scripting (XSS) - DOM, which allows an attacker to inject malicious scripts into a website. This can lead to unauthorized access to sensitive data or taking control of user sessions.
Recommendations For versions prior to 3.0.0-rc.13, update to version 3.0.0-rc.13 or later to resolve the issue.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-4414

Affected Products

Nuxt/Framework