3.5
CVSSv2

CVE-2022-22117

Published: 10/01/2022 Updated: 14/01/2022
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

In Directus, versions 9.0.0-alpha.4 up to and including 9.4.1 allow unrestricted file upload of .html files in the media upload functionality, which leads to Cross-Site Scripting vulnerability. A low privileged attacker can upload a crafted HTML file as a profile avatar, and when an admin or another user opens it, the XSS payload gets triggered.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

rangerstudio directus 9.0.0

rangerstudio directus