{"id":"CVE-2022-29362","details":"A cross-site scripting (XSS) vulnerability in /navigation/create?ParentID=%23 of ZKEACMS v3.5.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the ParentID parameter.","aliases":["GHSA-hc72-vj3g-5g2g"],"modified":"2026-04-10T04:47:12.844956Z","published":"2022-05-25T01:15:07.320Z","references":[{"type":"FIX","url":"https://github.com/SeriaWei/ZKEACMS/issues/457"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/seriawei/zkeacms","events":[{"introduced":"0"},{"last_affected":"e6e94be9329c4781e185487a934b58e5b7f4bb44"}],"database_specific":{"versions":[{"introduced":"0"},{"last_affected":"3.5.2"}]}}],"versions":["v1.0","v1.2","v3.1.3","v3.1.4","v3.1.5","v3.1.7","v3.1.9","v3.2.0","v3.2.1","v3.2.2","v3.2.3","v3.3","v3.3.1","v3.3.1.0","v3.3.2","v3.3.3","v3.3.4","v3.3.5","v3.3.6","v3.3.7","v3.4","v3.4.1","v3.4.2","v3.4.3","v3.4.4","v3.4.5","v3.5","v3.5.1","v3.5.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-29362.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}