PT-2022-6869 · Microsoft+1 · Internet Explorer+1

Michael Prentice

·

Published

2022-07-15

·

Updated

2025-07-15

·

CVE-2022-25869

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions angular versions prior to the fixed version
Description The issue is related to Cross-site Scripting (XSS) due to insecure page caching in the Internet Explorer browser, allowing interpolation of elements. This occurs because the application does not take adequate measures to protect the structure of web pages, potentially enabling a remote attacker to conduct an XSS attack.
Recommendations For all versions of angular, consider migrating to the actively maintained package @angular/core to receive security updates, as the angular package is deprecated. As a temporary workaround, consider restricting the use of the insecure page caching feature in the Internet Explorer browser until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

BDU:2023-05242
CVE-2022-25869
GHSA-PRC3-VJFX-VHM9
SNYK-JAVA-ORGWEBJARSBOWER-2949783
SNYK-JAVA-ORGWEBJARSBOWERGITHUBANGULAR-2949784
SNYK-JAVA-ORGWEBJARSNPM-2949782
SNYK-JS-ANGULAR-2949781

Affected Products

Debian
Internet Explorer