← Back

CVE-2022-42466

nvd nist
Published: Oct 19, 2022Modified: Jun 17, 2026

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

Prior to 2.0.0-M9, it was possible for an end-user to set the value of an editable string property of a domain object to a value that would be rendered unchanged when the value was saved. In particular, the end-user could enter javascript or similar and this would be executed. As of this release, the inputted strings are properly escaped when rendered.

Affected (9)

Products: Apache: Isis
1 product
Isis
Configuration A
9 vulnerable
Vulnerable SoftwareAffected Versions
Apache
Before 2.0.0
Version 2.0.0 milestone1
Version 2.0.0 milestone2
Version 2.0.0 milestone3
Version 2.0.0 milestone4
Version 2.0.0 milestone5
Version 2.0.0 milestone6
Version 2.0.0 milestone7
Version 2.0.0 milestone8

References (4)

Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Mailing ListVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListVendor Advisory

Timeline

No history available yet.