PT-2022-28043 · Unknown+2 · Graphite Web+2

Risicle

·

Published

2022-12-24

·

Updated

2023-08-09

·

CVE-2022-4729

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Graphite Web (affected versions not specified)
Description A problem was found in Graphite Web that affects some unknown processing of the component Template Name Handler. The manipulation leads to cross-site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Recommendations To fix this issue, it is recommended to apply a patch. The name of the patch is 2f178f490e10efc03cd1d27c72f64ecab224eb23. As a temporary workaround, consider restricting access to the Template Name Handler component until a patch is available.

Exploit

Fix

Improper Neutralization

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-4729
DLA-3309-1
GHSA-Q99P-78HP-XG5C
USN-6243-1
USN-6243-2

Affected Products

Graphite Web
Linuxmint
Ubuntu