CVE-2022-32176
Summary
| CVE | CVE-2022-32176 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-10-17 19:15:00 UTC |
| Updated | 2023-11-07 03:47:00 UTC |
| Description | In "Gin-Vue-Admin", versions v2.5.1 through v2.5.3b are vulnerable to Unrestricted File Upload that leads to execution of javascript code, through the "Compress Upload" functionality to the Media Library. When an admin user views the uploaded file, a low privilege attacker will get access to the admin's cookie leading to account takeover. |
Risk And Classification
Problem Types: CWE-434
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Gin-vue-admin Project | Gin-vue-admin | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2022-32176 | Mend Vulnerability Database | MISC | www.mend.io | |
| gin-vue-admin/image.vue at v2.5.3beta · flipped-aurora/gin-vue-admin · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Mend Vulnerability Research Team (MVR)
There are currently no legacy QID mappings associated with this CVE.