CVE-2022-32171 describes a Stored Cross-Site Scripting (XSS) vulnerability in Zinc versions v0.1.9 through v0.3.1. This flaw allows an authenticated attacker to inject a malicious JavaScript payload into the user ID field, which executes when another authenticated user attempts to delete that user. Successful exploitation could lead to credential theft. While the CVSS score is unavailable, the FAUCET Risk Score is low at 4/100, and there is no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.1.9, <= 0.3.1CPE matchmatch criteria | cpe:2.3:a:zinclabs:zinc:*:*:*:*:*:*:*:* |
CVSS data has not been published for this CVE.
No media coverage found for this CVE.