CVE-2022-23074

Published
View on NVD ↗
CVSS v3
N/A
CVSS v2
3.5
LOW
Affected
1
PROJECT

Description

In Recipes, versions 0.17.0 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in the ‘Name’ field of Keyword, Food and Unit components. When a victim accesses the Keyword/Food/Unit endpoints, the XSS payload will trigger. A low privileged attacker will have the victim's API key and can lead to admin's account takeover.

Application for managing recipes, planning meals, building shopping lists and much much more!
GitHubGitHub
8.38K