CVE-2022-25869
Description
All versions of the package angular; all versions of the package angularjs.core; all versions of the package angularjs are vulnerable to Cross-site Scripting (XSS) due to insecure page caching in the Internet Explorer browser, which allows interpolation of <textarea> elements.
CWE
- CWE-79 — Cross-site Scripting (XSS)
Affected
- n/a / angular — v=0 <* [affected]
- n/a / org.webjars.npm:angular — v=0 <* [affected]
- n/a / org.webjars.bower:angular — v=0 <* [affected]
- n/a / org.webjars.bowergithub.angular:angular — v=0 <* [affected]
- n/a / AngularJS.Core — v=0 <* [affected]
- n/a / angularjs — v=0 <* [affected]
CVSS
- 3.1 score=4.2 severity=MEDIUM
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N/E:P
References
- https://security.snyk.io/vuln/SNYK-JS-ANGULAR-2949781
- https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-2949782
- https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-2949783
- https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBANGULAR-2949784
- https://security.snyk.io/vuln/SNYK-DOTNET-ANGULARJSCORE-6084031
- https://security.snyk.io/vuln/SNYK-DOTNET-ANGULARJS-10771617
- https://neverendingsupport.github.io/angularjs-poc-cve-2022-25869
Source
cvelistV5-main/cves/2022/25xxx/CVE-2022-25869.json