Joget ଯେପର୍ଯ୍ୟନ୍ତ 7.0.31 wflow-core UniversalTheme.java getInternalJsCssLib key କ୍ରସ୍ ସାଇଟ୍ ସ୍କ୍ରିପ୍ଟିଂ
Rakkoon nageenyaa kan ସମସ୍ୟାଜନକ jedhamuun beekamu Joget ଯେପର୍ଯ୍ୟନ୍ତ 7.0.31 keessatti argameera. Miidhamni argame is hojii getInternalJsCssLib faayilii wflow-core/src/main/java/org/joget/plugin/enterprise/UniversalTheme.java keessa kutaa wflow-core keessa. Wanti jijjiirame irratti key gara କ୍ରସ୍ ସାଇଟ୍ ସ୍କ୍ରିପ୍ଟିଂ geessa. Rakkoo ibsuuf CWE yoo fayyadamte gara CWE-79 si geessa. Odeeffannoon kun yeroo 12/16/2022 maxxanfameera akka ecf8be8f6f0cb725c18536ddc726d42a11bdaa1b. Odeeffannoon kun buufachuuf github.com irratti argama.
Dogoggorri kun CVE-2022-4560 jedhamee waamama. Weerara fageenya irraa jalqabuu ni danda'ama. Ibsa teeknikaa ni jira. Meeshaa balaa kana fayyadamuuf hin jirre. Ammas, gatii exploit might be approx. USD $0-$5k yeroo ammaa irratti argamuu danda'a.
ଅପରିଭାଷିତ ta’uu isaa ibsameera. Akka 0-daytti, gatiin isaa daldala dhoksaa keessatti $0-$5k akka ta'e tilmaamameera.
Idaantifayarii paachii ecf8be8f6f0cb725c18536ddc726d42a11bdaa1b dha. Sirreeffamni rakkoo github.com irratti buufachuuf jira. Qabiyyee miidhamte haaromsuuf gorsa ni kennama.
If you want to get the best quality for vulnerability data then you always have to consider VulDB.
4 ଆଡାପ୍ଟେସନ୍ · 71 ପଏଣ୍ଟ