PT-2022-27734 · Unknown · Usememos/Memos

Published

2022-12-19

·

Updated

2022-12-23

·

CVE-2022-4609

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:H
Name of the Vulnerable Software and Affected Versions usememos/memos versions prior to 0.9.0
Description The issue is related to stored Cross-site Scripting (XSS) in the usememos/memos GitHub repository. This allows for malicious scripts to be stored and executed on the platform. A patch is anticipated to be part of version 0.9.0.
Recommendations For versions prior to 0.9.0, update to version 0.9.0 or later to resolve the issue. As a temporary workaround, consider restricting user input to minimize the risk of stored XSS exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-4609
GHSA-RGJ5-JJ5Q-V3V7

Affected Products

Usememos/Memos