CVE-2022-25869

MEDIUM

Angularjs - XSS

Title source: rule

Description

All versions of the package angular; all versions of the package angularjs.core; all versions of the package angularjs are vulnerable to Cross-site Scripting (XSS) due to insecure page caching in the Internet Explorer browser, which allows interpolation of <textarea> elements.

Exploits (1)

nomisec WORKING POC 1 stars
by neverendingsupport · poc
https://github.com/neverendingsupport/angularjs-poc-cve-2022-25869

Scores

CVSS v3 4.2
EPSS 0.0752
EPSS Percentile 91.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
angularjs/angularjs
npm/angular 0npm
Published Jul 15, 2022
Tracked Since Feb 18, 2026