{"id":"CVE-2022-4513","summary":"European Environment Agency eionet.contreg cross site scripting","details":"A vulnerability, which was classified as problematic, has been found in European Environment Agency eionet.contreg. This issue affects some unknown processing. The manipulation of the argument searchTag/resourceUri leads to cross site scripting. The attack may be initiated remotely. Upgrading to version 2022-06-27T0948 is able to address this issue. The name of the patch is a120c2153e263e62c4db34a06ab96a9f1c6bccb6. It is recommended to upgrade the affected component. The identifier VDB-215885 was assigned to this vulnerability.","modified":"2026-08-12T13:33:38.154595Z","published":"2022-12-15T00:00:00Z","database_specific":{"cna_assigner":"VulDB","cwe_ids":["CWE-707"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/4xxx/CVE-2022-4513.json"},"references":[{"type":"WEB","url":"https://github.com/eea/eionet.contreg/releases/tag/2022-06-27T0948"},{"type":"WEB","url":"https://vuldb.com/?id.215885"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/4xxx/CVE-2022-4513.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-4513"},{"type":"FIX","url":"https://github.com/eea/eionet.contreg/commit/a120c2153e263e62c4db34a06ab96a9f1c6bccb6"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/eea/eionet.contreg","events":[{"introduced":"0"},{"fixed":"ebb5bac8dfb020554a36fa015a1c3bef700adce8"},{"fixed":"a120c2153e263e62c4db34a06ab96a9f1c6bccb6"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:eea:eionet_content_registry:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2022-06-27t0948"}]}}],"versions":["2022-05-24T1407","2022-04-14T1147","2022-01-14T1523","2021-12-20T1143","2021-12-15T1157","2021-12-06T1417","2021-10-18T1514","2021-08-10T0913"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-4513.json","vanir_signatures_modified":"2026-08-12T13:33:38Z","vanir_signatures":[{"source":"https://github.com/eea/eionet.contreg/commit/a120c2153e263e62c4db34a06ab96a9f1c6bccb6","target":{"file":"src/main/java/eionet/cr/web/action/factsheet/FactsheetActionBean.java","function":"setUri"},"deprecated":false,"digest":{"length":61,"function_hash":"291766690054689174007335976283353075022"},"id":"CVE-2022-4513-3ddb2cb2","signature_type":"Function","signature_version":"v1"},{"deprecated":false,"digest":{"line_hashes":["109716919426651240874763354902061270573","50971795767043370246865493425822085841","43705636024550604102539654960742358331","115573468973361860569008290543740021383"],"threshold":0.9},"id":"CVE-2022-4513-77ed2ea6","signature_type":"Line","signature_version":"v1","source":"https://github.com/eea/eionet.contreg/commit/a120c2153e263e62c4db34a06ab96a9f1c6bccb6","target":{"file":"src/main/java/eionet/cr/web/action/factsheet/FactsheetActionBean.java"}},{"source":"https://github.com/eea/eionet.contreg/commit/a120c2153e263e62c4db34a06ab96a9f1c6bccb6","target":{"file":"src/main/java/eionet/cr/web/action/TagSearchActionBean.java"},"deprecated":false,"digest":{"line_hashes":["44009963968453302676748712366949947276","331551094413578595634944611216908208772","201387197250488008082750346311107453299","72858227104987213436395399215477680001","40829780042211735530104363448623988551","288130195056198940585807537526708082867","174456401461637494251451368174855139381","271310014619308501437625874547082334968"],"threshold":0.9},"id":"CVE-2022-4513-7a450272","signature_type":"Line","signature_version":"v1"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"}]}