PT-2022-21135 · Zinc · Zinc

CVE-2022-32172

·

Published

2022-10-06

·

Updated

2024-08-20

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Zinc versions v0.1.9 through v0.3.1
Description The issue concerns Stored Cross-Site Scripting in Zinc when using the delete template functionality. If an authenticated user deletes a template with a XSS payload in the name field, the Javascript payload will be executed, allowing an attacker to access the user’s credentials.
Recommendations For versions v0.1.9 through v0.3.1, consider disabling the delete template functionality until a patch is available to prevent exploitation of the Stored Cross-Site Scripting issue. Restrict access to the template deletion feature to minimize the risk of credential exposure.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-32172
GHSA-7J6X-42MM-P7JM
GO-2023-1896

Affected Products

Zinc