CVE-2022-32172 is a Stored Cross-Site Scripting (XSS) vulnerability affecting Zinc versions v0.1.9 through v0.3.1. An authenticated attacker can inject a JavaScript payload into the template name field, which executes when another user deletes that template, potentially compromising user credentials. While no CVSS score is provided, the vulnerability has a FAUCET Risk Score of 4/100, indicating low severity. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.1.9, <= 0.3.1CPE matchmatch criteria | cpe:2.3:a:zinclabs:zinc:*:*:*:*:*:*:*:* |
CVSS data has not been published for this CVE.
No media coverage found for this CVE.