← Back to CVE List

CVE-2022-23065

Published: 2022-05-02T13:15Z
Last Modified: 2024-11-21T06:47Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
In Vendure versions 0.1.0-alpha.2 to 1.5.1 are affected by Stored XSS vulnerability, where an attacker having catalog permission can upload a SVG file that contains malicious JavaScript into the “Assets” tab. The uploaded file will affect administrators as well as regular users. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt