CVE-2022-22115 is a critical Stored Cross-Site Scripting (XSS) vulnerability affecting Teedy versions v1.5 through v1.9. An attacker with low privileges can inject malicious scripts into the name of a Tag due to improper sanitization, which are then executed when a user views the edit tag page. This vulnerability carries a CVSS score of 9.0 (Critical) because it can lead to full account takeover, including privilege escalation, if a highly privileged administrator is targeted. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion with 10 mentions, indicating awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.5, <= 1.9CPE matchmatch criteria | cpe:2.3:a:sismics:teedy:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.6 Bluesky, 0.3 Mastodon, and 1.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.