{"id":"CVE-2022-4735","summary":"asrashley dash-live DOM Node media.js ready cross site scripting","details":"A vulnerability classified as problematic was found in asrashley dash-live. This vulnerability affects the function ready of the file static/js/media.js of the component DOM Node Handler. The manipulation leads to cross site scripting. The attack can be initiated remotely. The name of the patch is 24d01757a5319cc14c4aa1d8b53d1ab24d48e451. It is recommended to apply a patch to fix this issue. VDB-216766 is the identifier assigned to this vulnerability.","modified":"2026-08-12T03:51:39.958668482Z","published":"2022-12-25T15:59:34.306Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/4xxx/CVE-2022-4735.json","cna_assigner":"VulDB","cwe_ids":["CWE-79"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/4xxx/CVE-2022-4735.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-4735"},{"type":"ADVISORY","url":"https://vuldb.com/?id.216766"},{"type":"REPORT","url":"https://github.com/asrashley/dash-live/pull/7"},{"type":"REPORT","url":"https://vuldb.com/?ctiid.216766"},{"type":"FIX","url":"https://github.com/asrashley/dash-live/commit/24d01757a5319cc14c4aa1d8b53d1ab24d48e451"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/asrashley/dash-live","events":[{"introduced":"0"},{"fixed":"24d01757a5319cc14c4aa1d8b53d1ab24d48e451"}],"database_specific":{"source":"REFERENCES"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-4735.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"}]}