CVE-2022-43706 describes a cross-site scripting (XSS) vulnerability in the Web UI of StackStorm versions prior to 3.8.0. This flaw allows authenticated users with write access to pack rules to inject malicious scripts or HTML, which could then execute in the browsers of other logged-in users. The vulnerability carries a CVSS score of 5.4 (Medium), indicating a low attack complexity and requiring user interaction, with potential impacts on confidentiality and integrity. The attack vector is over the network, but requires prior authentication and specific permissions. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting it is not a widely recognized or actively targeted threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.8.0CPE matchmatch criteria | cpe:2.3:a:stackstorm:stackstorm:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.