Lucene search

K
cveMendCVE-2022-23074
HistoryJun 21, 2022 - 10:15 a.m.

CVE-2022-23074

2022-06-2110:15:08
CWE-79
Mend
web.nvd.nist.gov
645
cve
2022
23074
stored
xss
recipes
security vulnerability
nvd
api key
admin account takeover

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

EPSS

0

Percentile

12.8%

In Recipes, versions 0.17.0 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in the ‘Name’ field of Keyword, Food and Unit components. When a victim accesses the Keyword/Food/Unit endpoints, the XSS payload will trigger. A low privileged attacker will have the victim’s API key and can lead to admin’s account takeover.

Affected configurations

Nvd
Node
tandoorrecipesRange0.17.01.2.5
VendorProductVersionCPE
tandoorrecipes*cpe:2.3:a:tandoor:recipes:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "recipes",
    "vendor": "recipes",
    "versions": [
      {
        "lessThan": "unspecified",
        "status": "affected",
        "version": "0.17.0",
        "versionType": "custom"
      },
      {
        "lessThanOrEqual": "1.2.5",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

EPSS

0

Percentile

12.8%

Related for CVE-2022-23074