Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-32177


In "Gin-Vue-Admin", versions v2.5.1 through v2.5.3beta are vulnerable to Unrestricted File Upload that leads to execution of javascript code, through the 'Normal Upload' functionality to the Media Library. When an admin user views the uploaded file, a low privilege attacker will get access to the admin’s cookie leading to account takeover.


Published

2022-10-14T07:15:09.057

Last Modified

2025-05-14T16:15:19.040

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.0 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-434
  • Type: Primary
    CWE-434

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application gin-vue-admin_project gin-vue-admin ≤ 2.5.2 Yes
Application gin-vue-admin_project gin-vue-admin 2.5.3 Yes

References