PT-2022-27706 · Alist · Alist

CVE-2022-45970

·

Published

2022-12-12

·

Updated

2025-04-22

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Alist version 3.5.1
Description The issue is related to Cross Site Scripting (XSS) via the bulletin board. This means an attacker could potentially inject malicious scripts into the website, affecting users who access the bulletin board.
Recommendations For Alist version 3.5.1, as a temporary workaround, consider restricting access to the bulletin board until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-45970
GHSA-957M-G6RF-4C2M

Affected Products

Alist