Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-43718


Upload data forms do not correctly render user input leading to possible XSS attack vectors that can be performed by authenticated users with database connection update permissions. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0.


Published

2023-01-16T11:15:10.443

Last Modified

2025-04-07T16:15:18.047

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.4 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apache superset ≤ 1.5.2 Yes
Application apache superset 2.0.0 Yes
Application apache superset 2.0.0 Yes
Application apache superset 2.0.0 Yes

References