VYPR
Medium severity5.4NVD Advisory· Published May 2, 2022· Updated Jun 17, 2026

CVE-2022-23065

CVE-2022-23065

Description

In Vendure versions 0.1.0-alpha.2 to 1.5.1 are affected by Stored XSS vulnerability, where an attacker having catalog permission can upload a SVG file that contains malicious JavaScript into the “Assets” tab. The uploaded file will affect administrators as well as regular users.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

19
  • Vendure/Vendure17 versions
    cpe:2.3:a:vendure:vendure:*:*:*:*:*:*:*:*+ 16 more
    • cpe:2.3:a:vendure:vendure:*:*:*:*:*:*:*:*range: >=0.1.2,<=1.5.1
    • cpe:2.3:a:vendure:vendure:0.1.0:alpha10:*:*:*:*:*:*
    • cpe:2.3:a:vendure:vendure:0.1.0:alpha11:*:*:*:*:*:*
    • cpe:2.3:a:vendure:vendure:0.1.0:alpha12:*:*:*:*:*:*
    • cpe:2.3:a:vendure:vendure:0.1.0:alpha13:*:*:*:*:*:*
    • cpe:2.3:a:vendure:vendure:0.1.0:alpha14:*:*:*:*:*:*
    • cpe:2.3:a:vendure:vendure:0.1.0:alpha15:*:*:*:*:*:*
    • cpe:2.3:a:vendure:vendure:0.1.0:alpha16:*:*:*:*:*:*
    • cpe:2.3:a:vendure:vendure:0.1.0:alpha18:*:*:*:*:*:*
    • cpe:2.3:a:vendure:vendure:0.1.0:alpha2:*:*:*:*:*:*
    • cpe:2.3:a:vendure:vendure:0.1.0:alpha3:*:*:*:*:*:*
    • cpe:2.3:a:vendure:vendure:0.1.0:alpha4:*:*:*:*:*:*
    • cpe:2.3:a:vendure:vendure:0.1.0:alpha5:*:*:*:*:*:*
    • cpe:2.3:a:vendure:vendure:0.1.0:alpha6:*:*:*:*:*:*
    • cpe:2.3:a:vendure:vendure:0.1.0:alpha7:*:*:*:*:*:*
    • cpe:2.3:a:vendure:vendure:0.1.0:alpha8:*:*:*:*:*:*
    • cpe:2.3:a:vendure:vendure:0.1.0:alpha9:*:*:*:*:*:*
  • Vendure Ecommerce/vendurellm-create2 versions
    0.1.0-alpha.2 to 1.5.1+ 1 more
    • (no CPE)range: 0.1.0-alpha.2 to 1.5.1
    • (no CPE)range: 0.1.0-alpha.2

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.