CyberRota Analysis
This is a low severity vulnerability with a CVSS score of 3.7. It affects Java. Exploitation may require the attacker to be authenticated.
CVE
CVE-2022-35230
Severity
LOW
CVSS
3.7
EPSS
0.72%
Java
Original NVD Description
An authenticated user can create a link with reflected Javascript code inside it for the graphs page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict.
Related CVEs
Other vulnerabilities affecting the same vendor(s)