peter bassill · operator
$ cve CVE-2022-47877 JSON

CVE-2022-47877 EXPLOIT

5.4
MEDIUM · CVSS 3.1 · EPSS 2.6% (pctl 85)

Patch early

A public exploit exists.

Description

A Stored cross-site scripting vulnerability in Jedox 2020.2.5 allows remote, authenticated users to inject arbitrary web script or HTML in the Logs page via the log module 'log'.

Scoring

CVSS5.4 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS2.63% — more likely to be exploited than 85% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2023-05-02
Last modified2026-06-17

Affected (1)

VendorProduct
jedoxjedox

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD