Advisories ยป MGASA-2024-0074

Updated cherrytree packages fix security vulnerability

Publication date: 20 Mar 2024
Modification date: 20 Mar 2024
Type: security
Affected Mageia releases : 9
CVE: CVE-2022-35133

Description

A cross-site scripting (XSS) vulnerability in CherryTree v0.99.30 allows
attackers to execute arbitrary web scripts or HTML via a crafted payload
injected into the Name text field when creating a node. (CVE-2022-35133)
                

References

SRPMS

9/core