CVE-2022-25229
Summary
| CVE | CVE-2022-25229 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-05-20 11:15:00 UTC |
| Updated | 2022-05-31 14:30:00 UTC |
| Description | Popcorn Time 0.4.7 has a Stored XSS in the 'Movies API Server(s)' field via the 'settings' page. The 'nodeIntegration' configuration is set to on which allows the 'webpage' to use 'NodeJs' features, an attacker can leverage this to run OS commands. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Popcorn Time Project | Popcorn Time | 0.4.7 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Popcorn Time 0.4.7 - XSS to RCE · Issue #2491 · popcorn-official/popcorn-desktop · GitHub | MISC | github.com | |
| Popcorn Time 0.4.7 - XSS to RCE | Fluid Attacks | MISC | fluidattacks.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.