← Back

CVE-2022-22117

nvd nist
Published: Jan 10, 2022Modified: Nov 21, 2024

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: vulnerabilitylab@mend.io (Secondary)

Description

In Directus, versions 9.0.0-alpha.4 through 9.4.1 allow unrestricted file upload of .html files in the media upload functionality, which leads to Cross-Site Scripting vulnerability. A low privileged attacker can upload a crafted HTML file as a profile avatar, and when an admin or another user opens it, the XSS payload gets triggered.

Affected (153)

1 product
Directus
Configuration A
153 vulnerable
Vulnerable SoftwareAffected Versions
Rangerstudio
From 9.0.1 to 9.4.1
Version 9.0.0
Version 9.0.0 alpha10
Version 9.0.0 alpha11
Version 9.0.0 alpha12
Version 9.0.0 alpha13
Version 9.0.0 alpha14
Version 9.0.0 alpha15
Version 9.0.0 alpha16
Version 9.0.0 alpha17
Version 9.0.0 alpha18
Version 9.0.0 alpha19
Version 9.0.0 alpha20
Version 9.0.0 alpha21
Version 9.0.0 alpha22
Version 9.0.0 alpha23
Version 9.0.0 alpha24
Version 9.0.0 alpha25
Version 9.0.0 alpha26
Version 9.0.0 alpha27
Version 9.0.0 alpha31
Version 9.0.0 alpha32
Version 9.0.0 alpha33
Version 9.0.0 alpha34
Version 9.0.0 alpha35
Version 9.0.0 alpha36
Version 9.0.0 alpha37
Version 9.0.0 alpha38
Version 9.0.0 alpha39
Version 9.0.0 alpha40
Version 9.0.0 alpha41
Version 9.0.0 alpha42
Version 9.0.0 alpha4
Version 9.0.0 alpha5
Version 9.0.0 alpha6
Version 9.0.0 alpha7
Version 9.0.0 alpha8
Version 9.0.0 alpha9
Version 9.0.0 beta0
Version 9.0.0 beta10
Version 9.0.0 beta11
Version 9.0.0 beta12
Version 9.0.0 beta13
Version 9.0.0 beta14
Version 9.0.0 beta1
Version 9.0.0 beta2
Version 9.0.0 beta3
Version 9.0.0 beta4
Version 9.0.0 beta5
Version 9.0.0 beta7
Version 9.0.0 beta8
Version 9.0.0 beta9
Version 9.0.0 rc0
Version 9.0.0 rc100
Version 9.0.0 rc101
Version 9.0.0 rc10
Version 9.0.0 rc11
Version 9.0.0 rc12
Version 9.0.0 rc13
Version 9.0.0 rc14
Version 9.0.0 rc15
Version 9.0.0 rc17
Version 9.0.0 rc18
Version 9.0.0 rc19
Version 9.0.0 rc1
Version 9.0.0 rc20
Version 9.0.0 rc21
Version 9.0.0 rc22
Version 9.0.0 rc23
Version 9.0.0 rc24
Version 9.0.0 rc25
Version 9.0.0 rc26
Version 9.0.0 rc27
Version 9.0.0 rc28
Version 9.0.0 rc29
Version 9.0.0 rc2
Version 9.0.0 rc30
Version 9.0.0 rc31
Version 9.0.0 rc32
Version 9.0.0 rc33
Version 9.0.0 rc34
Version 9.0.0 rc35
Version 9.0.0 rc36
Version 9.0.0 rc37
Version 9.0.0 rc38
Version 9.0.0 rc39
Version 9.0.0 rc3
Version 9.0.0 rc40
Version 9.0.0 rc41
Version 9.0.0 rc42
Version 9.0.0 rc43
Version 9.0.0 rc44
Version 9.0.0 rc45
Version 9.0.0 rc46
Version 9.0.0 rc47
Version 9.0.0 rc48
Version 9.0.0 rc49
Version 9.0.0 rc4
Version 9.0.0 rc50
Version 9.0.0 rc51
Version 9.0.0 rc52
Version 9.0.0 rc53
Version 9.0.0 rc54
Version 9.0.0 rc55
Version 9.0.0 rc56
Version 9.0.0 rc57
Version 9.0.0 rc58
Version 9.0.0 rc59
Version 9.0.0 rc5
Version 9.0.0 rc60
Version 9.0.0 rc61
Version 9.0.0 rc62
Version 9.0.0 rc63
Version 9.0.0 rc64
Version 9.0.0 rc65
Version 9.0.0 rc66
Version 9.0.0 rc67
Version 9.0.0 rc68
Version 9.0.0 rc69
Version 9.0.0 rc6
Version 9.0.0 rc70
Version 9.0.0 rc71
Version 9.0.0 rc72
Version 9.0.0 rc73
Version 9.0.0 rc74
Version 9.0.0 rc75
Version 9.0.0 rc76
Version 9.0.0 rc77
Version 9.0.0 rc78
Version 9.0.0 rc79
Version 9.0.0 rc7
Version 9.0.0 rc80
Version 9.0.0 rc81
Version 9.0.0 rc82
Version 9.0.0 rc83
Version 9.0.0 rc84
Version 9.0.0 rc85
Version 9.0.0 rc86
Version 9.0.0 rc87
Version 9.0.0 rc88
Version 9.0.0 rc89
Version 9.0.0 rc8
Version 9.0.0 rc90
Version 9.0.0 rc91
Version 9.0.0 rc92
Version 9.0.0 rc93
Version 9.0.0 rc94
Version 9.0.0 rc95
Version 9.0.0 rc96
Version 9.0.0 rc97
Version 9.0.0 rc98
Version 9.0.0 rc99
Version 9.0.0 rc9

References (4)

Source: vulnerabilitylab@mend.io
PatchThird Party Advisory
Source: vulnerabilitylab@mend.io
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory

Timeline

No history available yet.