CyberRota Analysis
This is a low severity vulnerability with a CVSS score of 3.7. It affects Java. Exploitation may require the attacker to be authenticated.
CVE
CVE-2022-35229
Severity
LOW
CVSS
3.7
EPSS
0.73%
Java
Original NVD Description
An authenticated user can create a link with reflected Javascript code inside it for the discovery page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict.
Related CVEs
Other vulnerabilities affecting the same vendor(s)