{"id":"CVE-2022-48197","details":"Reflected cross-site scripting (XSS) exists in Sandbox examples in the YUI2 repository. The download distributions, TreeView component and the YUI Javascript library overall are not affected. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.","modified":"2026-04-10T04:53:26.957493Z","published":"2023-01-02T16:15:10.997Z","references":[{"type":"WEB","url":"http://packetstormsecurity.com/files/171633/Yahoo-User-Interface-TreeView-2.8.2-Cross-Site-Scripting.html"},{"type":"WEB","url":"https://github.com/yui/yui2/blob/yui2-2.8.2-8/sandbox/treeview/inc-rightbar.php"},{"type":"WEB","url":"https://literatejava.com/security/is-it-really-a-cve-reported-xss-in-yui-2-8-2/"},{"type":"ADVISORY","url":"https://github.com/ryan412/CVE-2022-48197/blob/main/README.md"},{"type":"ADVISORY","url":"https://github.com/yui/yui2/tags"},{"type":"PACKAGE","url":"https://github.com/ryan412/CVE-2022-48197"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/yui/yui2","events":[{"introduced":"45f9b6d1d5df07407a2fc97951b17eeba8f3fc53"},{"last_affected":"159208465da41a4796716d8a5bf833c6778b3f61"}],"database_specific":{"versions":[{"introduced":"2000"},{"last_affected":"2800"}]}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-48197.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}