{"id":"UBUNTU-CVE-2022-35133","details":"A cross-site scripting (XSS) vulnerability in CherryTree v0.99.30 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name text field when creating a node.","modified":"2026-05-20T16:07:59.599473174Z","published":"2022-08-17T21:15:00Z","upstream":["CVE-2022-35133"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2022-35133"},{"type":"REPORT","url":"https://drive.google.com/file/d/1Pidkh2MAQkue81dS7SI-d16Vun_s5tot/view?usp=sharing"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2022-35133"}],"affected":[{"package":{"name":"cherrytree","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/cherrytree?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.35.10-1","0.35.11-1","0.36.2-1","0.36.3-1","0.36.4-1"],"ecosystem_specific":{"binaries":[{"binary_name":"cherrytree","binary_version":"0.36.4-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-35133.json"}},{"package":{"name":"cherrytree","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/cherrytree?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.37.6-1","0.37.6-1.1"],"ecosystem_specific":{"binaries":[{"binary_name":"cherrytree","binary_version":"0.37.6-1.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-35133.json"}},{"package":{"name":"cherrytree","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/cherrytree?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.99.40+dfsg-1","0.99.43+dfsg-1build1"],"ecosystem_specific":{"binaries":[{"binary_name":"cherrytree","binary_version":"0.99.43+dfsg-1build1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-35133.json"}},{"package":{"name":"cherrytree","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/cherrytree?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.99.48+dfsg-1","1.0.2+dfsg-1","1.0.2+dfsg-1build2","1.0.2+dfsg-1build3","1.1.2+dfsg-1"],"ecosystem_specific":{"binaries":[{"binary_name":"cherrytree","binary_version":"1.1.2+dfsg-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-35133.json"}},{"package":{"name":"cherrytree","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/cherrytree?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.2.0+dfsg-1","1.2.0+dfsg-1build1"],"ecosystem_specific":{"binaries":[{"binary_version":"1.2.0+dfsg-1build1","binary_name":"cherrytree"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-35133.json"}},{"package":{"name":"cherrytree","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/cherrytree?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.2.0+dfsg-1build1","1.2.0+dfsg-1build2"],"ecosystem_specific":{"binaries":[{"binary_name":"cherrytree","binary_version":"1.2.0+dfsg-1build2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-35133.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},{"type":"Ubuntu","score":"medium"}]}