CVE-2022-48197 EXPLOIT
6.1
MEDIUM · CVSS 3.1 · EPSS 6.6% (pctl 94)
Patch early
A public exploit exists.
Description
Reflected cross-site scripting (XSS) exists in Sandbox examples in the YUI2 repository. The download distributions, TreeView component and the YUI Javascript library overall are not affected. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Scoring
| CVSS | 6.1 (MEDIUM, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
| EPSS | 6.61% — more likely to be exploited than 94% of all CVEs |
| Weakness | CWE-79 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2023-01-02 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| yui project | yui |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Yahoo User Interface library (YUI2) TreeView v2.8.2 - Multiple Reflected Cross Site Scripting (XSS) | 2023-04-01 |
References
- http://packetstormsecurity.com/files/171633/Yahoo-User-Interface-TreeView-2.8.2-Cross-Site-Scripting.html
- https://github.com/ryan412/CVE-2022-48197
- https://github.com/ryan412/CVE-2022-48197/blob/main/README.md
- https://github.com/yui/yui2/blob/yui2-2.8.2-8/sandbox/treeview/inc-rightbar.php
- https://github.com/yui/yui2/tags
- https://literatejava.com/security/is-it-really-a-cve-reported-xss-in-yui-2-8-2/
- http://packetstormsecurity.com/files/171633/Yahoo-User-Interface-TreeView-2.8.2-Cross-Site-Scripting.html
- https://github.com/ryan412/CVE-2022-48197
- https://github.com/ryan412/CVE-2022-48197/blob/main/README.md
- https://github.com/yui/yui2/blob/yui2-2.8.2-8/sandbox/treeview/inc-rightbar.php
- https://github.com/yui/yui2/tags
- https://literatejava.com/security/is-it-really-a-cve-reported-xss-in-yui-2-8-2/
→ the Explorer · watch your stack · NVD