CVE-2022-47968
MEDIUMCVSS 5.4/10EPSS 0.40%
Last modified
CVE-2022-47968 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. Heimdall Application Dashboard through 2.5.4 allows reflected and stored XSS via "Application name" to the "Add application" page. The stored XSS will be triggered in the "Application list" page.. EPSS estimates a 0.40% chance of exploitation in the next 30 days.
Description
Heimdall Application Dashboard through 2.5.4 allows reflected and stored XSS via "Application name" to the "Add application" page. The stored XSS will be triggered in the "Application list" page.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Linuxserver | Heimdall Application Dashboard | <= 2.5.4 |
References
- https://github.com/linuxserver/Heimdall/issues/1086Exploit, Issue Tracking, Third Party Advisory
- https://samy.link/blogThird Party Advisory
- https://github.com/linuxserver/Heimdall/issues/1086Exploit, Issue Tracking, Third Party Advisory
- https://samy.link/blogThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-47968?
Heimdall Application Dashboard through 2.5.4 allows reflected and stored XSS via "Application name" to the "Add application" page. The stored XSS will be triggered in the "Application list" page.
How severe is CVE-2022-47968?
CVE-2022-47968 has a CVSS score of 5.4/10 (MEDIUM severity). The EPSS model estimates a 0.40% probability of exploitation in the next 30 days.
How do I fix CVE-2022-47968?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-47951An issue was discovered in OpenStack Cinder before 19.1.2, 2…5.7
- CVE-2022-47952lxc-user-nic in lxc through 5.0.1 is installed setuid root, …3.3
- CVE-2022-4796Incorrect Use of Privileged APIs in GitHub repository usemem…8.1
- CVE-2022-47965The issue was addressed with improved memory handling. This …7.8
- CVE-2022-47966Multiple Zoho ManageEngine on-premise products, such as Serv…9.8
- CVE-2022-47967A vulnerability has been identified in Solid Edge (All versi…7.8
- CVE-2022-4797Improper Restriction of Excessive Authentication Attempts in…4.3
- CVE-2022-47974The Bluetooth AVRCP module has a vulnerability that can lead…6.5
- CVE-2022-47975The DUBAI module has a double free vulnerability. Successful…7.5
- CVE-2022-47976The DMSDP module of the distributed hardware has a vulnerabi…7.5
- CVE-2022-47977A vulnerability has been identified in JT Open (All versions…7.8
- CVE-2022-4798Authorization Bypass Through User-Controlled Key in GitHub r…5.3
Are you affected by CVE-2022-47968?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
