CVE-2022-4735

A vulnerability classified as problematic was found in asrashley dash-live. This vulnerability affects the function ready of the file static/js/media.js of the component DOM Node Handler. The manipulation leads to cross site scripting. The attack can be initiated remotely. The name of the patch is 24d01757a5319cc14c4aa1d8b53d1ab24d48e451. It is recommended to apply a patch to fix this issue. VDB-216766 is the identifier assigned to this vulnerability.
References
Link Resource
https://github.com/asrashley/dash-live/commit/24d01757a5319cc14c4aa1d8b53d1ab24d48e451 Patch Third Party Advisory
https://github.com/asrashley/dash-live/pull/7 Patch Third Party Advisory
https://vuldb.com/?ctiid.216766 Permissions Required Third Party Advisory
https://vuldb.com/?id.216766 Permissions Required Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:dash-live_project:dash-live:*:*:*:*:*:*:*:*

History

25 Dec 2022, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-12-25 16:15

Updated : 2024-05-17 02:16


NVD link : CVE-2022-4735

Mitre link : CVE-2022-4735

CVE.ORG link : CVE-2022-4735


JSON object : View

Products Affected

dash-live_project

  • dash-live
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')