CyberRota Analysis
This is a critical severity vulnerability with a CVSS score of 9.0. See the original NVD description below for full technical details.
CVE
CVE-2022-40289
Severity
CRITICAL
CVSS
9
EPSS
0.60%
Original NVD Description
The application was vulnerable to an authenticated Stored Cross-Site Scripting (XSS) in the upload and download functionality, which could be leveraged to escalate privileges or compromise any accounts they can coerce into observing the targeted files.
Related CVEs
Other vulnerabilities affecting the same vendor(s)