Skip to content

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in MyGraph

Moderate
renlm published GHSA-hj4j-923h-927j Sep 23, 2022

Package

maven MyGraph (Maven)

Affected versions

<1.0.4

Patched versions

1.0.4

Description

Impact

MyGraph is a permission management system.
MyGraph version 1.0.3 has a storage XSS vulnerability
Remote code execution vulnerability is a Web security vulnerability, we can execute any command, such as whoami.

Patches

https://github.com/renlm/MyGraph

Workarounds

After logging in to the background of MyGraph, you can add an XSS attack code in the "Project name" in the "Workbench" - "Knowledge Library" - "My Project" - "New", so that remote attackers can steal the user's personal information, or even phishing.

References

None

For more information

Add XSS utilization code.
Untitled
Set to public. The attacker can receive user information when other administrators access it.
image

Severity

Moderate

CVE ID

CVE-2022-39240

Weaknesses

Credits