cvedb.io
CVE-2022-3333
LOW · CVSS 3.5
EPSS exploitation probability: 0%
Published 2022-09-28T05:15:09.757 · Last modified 2026-06-17T04:59:19.407

Summary

A vulnerability, which was classified as problematic, was found in Zephyr Project Manager up to 3.2.4. Affected is an unknown function of the file /v1/tasks/create/ of the component REST Call Handler. The manipulation of the argument onanimationstart leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 3.2.5 is able to address this issue. It is recommended to upgrade the affected component. VDB-209370 is the identifier assigned to this vulnerability.

Affected products

zephyr-one — zephyr_project_manager

Does this affect you?

Add your gear to cvedb and we'll alert you only when zephyr-one ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.