CVE-2022-39824
8.9
HIGH
CVSS 3.1
EPSS 0.70%
Description
Server-side JavaScript injection in Appsmith through 1.7.14 allows remote attackers to execute arbitrary JavaScript code from the server via the currentItem property of the list widget, e.g., to perform DoS attacks or achieve an information leak.
How to fix CVE-2022-39824
To remediate CVE-2022-39824, upgrade the affected package to a fixed version below.
- Bitnami/appsmith—upgrade to 1.7.15 or later
Is CVE-2022-39824 being exploited?
Low — EPSS is 0.7%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 1.7.15
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.9 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:H |