Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-32176


In "Gin-Vue-Admin", versions v2.5.1 through v2.5.3b are vulnerable to Unrestricted File Upload that leads to execution of javascript code, through the "Compress Upload" functionality to the Media Library. When an admin user views the uploaded file, a low privilege attacker will get access to the admin's cookie leading to account takeover.


Published

2022-10-17T19:15:09.903

Last Modified

2025-05-27T21:08:02.240

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.0 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-434
  • Type: Primary
    CWE-434

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application gin-vue-admin_project gin-vue-admin ≤ 2.5.3b Yes

References