Security Advisory

CVE-2022-21948

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2023-02-07 00:00:00
Last updated 2025-03-25 17:34:02
Assigner suse
CVSS score 4.3
State PUBLISHED

Description

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in paste allows remote attackers to place Javascript into SVG files. This issue affects: openSUSE paste paste version b57b9f87e303a3db9465776e657378e96845493b and prior versions.