Medium severity6.1NVD Advisory· Published Sep 14, 2022· Updated Jun 17, 2026
CVE-2022-37724
CVE-2022-37724
Description
Project Wonder WebObjects 1.0 through 5.4.3 is vulnerable to Arbitrary HTTP Header injection and URL- or Header-based XSS reflection in all web-server adaptor interfaces.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
wonder:wonderMaven | >= 1.0, <= 7.3 | — |
Affected products
3- Project Wonder/WebObjectsdescription
Patches
Vulnerability mechanics
References
6- github.com/wocommunity/wonder/pull/992nvdPatchThird Party AdvisoryWEB
- xmit.xyz/security/webobjects-url-tomfoolery/nvdExploitMitigationThird Party Advisory
- github.com/advisories/GHSA-xv7r-9vq4-9wrqghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-37724ghsaADVISORY
- github.com/wocommunity/wonder/commit/b0d2d74f13203268ea254b02552600850f28014bghsaWEB
- xmit.xyz/security/webobjects-url-tomfooleryghsaWEB
News mentions
0No linked articles in our index yet.