Miggo Logo

CVE-2022-33154: brotkrueml/schema fails to properly encode user input for output in HTML context, leading to XSS

5.4

CVSS Score
3.1

Basic Information

EPSS Score
0.24749%
Published
6/17/2022
Updated
1/27/2023
KEV Status
No
Technology
TechnologyPHP

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Package NameEcosystemVulnerable VersionsFirst Patched Version
brotkrueml/schemacomposer>= 2.0.0, < 2.5.12.5.1
brotkrueml/schemacomposer< 1.13.11.13.1

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

T** *xt*nsion **ils to prop*rly *n*o** us*r input *or output in *TML *ont*xt. * TYPO* ***k*n* us*r ***ount is r*quir** to *xploit t** vuln*r**ility.

Reasoning

No *n*lysis *v*il**l*
CVE-2022-33154: TYPO3 Schema Auth Backend XSS | Miggo