VYPR
High severity8.9NVD Advisory· Published Sep 5, 2022· Updated Jun 17, 2026

CVE-2022-39824

CVE-2022-39824

Description

Server-side JavaScript injection in Appsmith through 1.7.14 allows remote attackers to execute arbitrary JavaScript code from the server via the currentItem property of the list widget, e.g., to perform DoS attacks or achieve an information leak.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • cpe:2.3:a:appsmith:appsmith:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:appsmith:appsmith:*:*:*:*:*:*:*:*range: <=1.7.14
    • (no CPE)
    • (no CPE)range: <=1.7.14
  • osv-coords
    Range: < 1.7.15

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.