CVE-2022-4927 is a problematic vulnerability affecting ualbertalib NEOSDiscovery versions prior to 1.0.71. It involves the use of an untrusted web link with window.opener access within the app/views/bookmarks/_refworks.html.erb file, allowing for remote initiation of an attack. Rated with a CVSS score of 6.1 (Medium), this vulnerability has a low attack complexity and requires user interaction, potentially leading to limited impact on confidentiality and integrity. Currently, there is no evidence of active exploitation, nor is there publicly available exploit code in Metasploit, Nuclei, or ExploitDB. The vulnerability has also received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.70CPE matchmatch criteria | cpe:2.3:a:ualberta:neosdiscovery:1.0.70:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.