Record summary

CVE-2022-35230 has a selected CVSS score of 3.7 (low).

Description

An authenticated user can create a link with reflected Javascript code inside it for the graphs page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict.

Description source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List4.0.0-4.0.42affected
5.0.0-5.0.24affected

References

4