{"id":"CVE-2022-48197","details":"Reflected cross-site scripting (XSS) exists in Sandbox examples in the YUI2 repository. The download distributions, TreeView component and the YUI Javascript library overall are not affected. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.","modified":"2026-08-12T03:51:23.078664265Z","published":"2023-01-02T00:00:00Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/48xxx/CVE-2022-48197.json"},"references":[{"type":"WEB","url":"http://packetstormsecurity.com/files/171633/Yahoo-User-Interface-TreeView-2.8.2-Cross-Site-Scripting.html"},{"type":"WEB","url":"https://github.com/ryan412/CVE-2022-48197/blob/main/README.md"},{"type":"WEB","url":"https://github.com/yui/yui2/blob/yui2-2.8.2-8/sandbox/treeview/inc-rightbar.php"},{"type":"WEB","url":"https://github.com/yui/yui2/tags"},{"type":"WEB","url":"https://literatejava.com/security/is-it-really-a-cve-reported-xss-in-yui-2-8-2/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/48xxx/CVE-2022-48197.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-48197"},{"type":"PACKAGE","url":"https://github.com/ryan412/CVE-2022-48197"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/yui/yui2","events":[{"introduced":"45f9b6d1d5df07407a2fc97951b17eeba8f3fc53"},{"last_affected":"159208465da41a4796716d8a5bf833c6778b3f61"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:yui_project:yui:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2000"},{"last_affected":"2800"}]}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-48197.json"}}],"schema_version":"1.9.0"}