CVE-2022-31192

HIGH

DSpace - XSS

Title source: llm

Description

DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui is a UI component for DSpace. The JSPUI "Request a Copy" feature does not properly escape values submitted and stored from the "Request a Copy" form. This means that item requests could be vulnerable to XSS attacks. This vulnerability only impacts the JSPUI. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Exploits (1)

nomisec WRITEUP
by shoucheng3 · poc
https://github.com/shoucheng3/DSpace__DSpace_CVE-2022-31192_5-100

Scores

CVSS v3 7.1
EPSS 0.0032
EPSS Percentile 54.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

Details

CWE
CWE-79
Status published
Products (2)
duraspace/dspace 4.0 - 5.10
org.dspace/dspace-jspui 5.0 - 5.11Maven
Published Aug 01, 2022
Tracked Since Feb 18, 2026