VYPR
Unrated severityNVD Advisory· Published May 29, 2022· Updated May 30, 2025

CVE-2022-24967

CVE-2022-24967

Description

Black Rainbow NIMBUS before 3.7.0 allows stored Cross-site Scripting (XSS).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS in Black Rainbow NIMBUS before 3.7.0 allows attackers to inject arbitrary JavaScript through crafted case data, leading to potential session hijacking.

Vulnerability

Black Rainbow NIMBUS versions prior to 3.7.0 contain a stored Cross-site Scripting (XSS) vulnerability. The application does not properly sanitize user input when creating or updating case data, allowing an attacker to store arbitrary HTML and JavaScript that will be executed in the browsers of other users viewing that content. [1]

Exploitation

An attacker with access to create or modify case data in NIMBUS (which may be any authenticated user depending on the deployment) can insert malicious script payloads into fields such as case descriptions or notes. When an administrator or other user views the crafted case, the script executes in their browser session, no further user interaction beyond viewing the page is required. [1]

Impact

Successful exploitation enables the attacker to perform actions within the context of the victim's session, such as exfiltrating session cookies, performing unauthorized actions, or defacing displayed content. The impact is limited by the browser's same-origin policy but can lead to account takeover or information disclosure if the victim has higher privileges. [1]

Mitigation

Black Rainbow has addressed the issue in NIMBUS version 3.7.0. Users running an earlier version should upgrade to 3.7.0 or later. No workarounds have been publicly documented. [1]

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.