{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-27T23:30:35.167","vulnerabilities":[{"cve":{"id":"CVE-2022-23637","sourceIdentifier":"security-advisories@github.com","published":"2022-02-14T21:15:09.777","lastModified":"2026-06-17T04:30:32.177","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"K-Box is a web-based application to manage documents, images, videos and geodata. Prior to version 0.33.1, a stored Cross-Site-Scripting (XSS) vulnerability is present in the markdown editor used by the document abstract and markdown file preview. A specifically crafted anchor link can, if clicked, execute untrusted javascript actions, like retrieving user cookies. Version 0.33.1 includes a patch that allows discarding unsafe links."},{"lang":"es","value":"K-Box es una aplicación basada en la web para administrar documentos, imágenes, vídeos y geodatos. En versiones anteriores a 0.33.1, se presenta una vulnerabilidad de tipo Cross-Site-Scripting (XSS) almacenada en el editor markdown usado por el resumen de documentos y la vista previa de archivos markdown. Un enlace ancla específicamente diseñado puede, si hace clic, ejecutar acciones javascript no confiables, como la recuperación de las cookies del usuario. La versión 0.33.1 incluye un parche que permite descartar los enlaces no seguros"}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"k-box","product":"k-box","versions":[{"version":"< 0.33.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-04-23T14:10:37.255416Z","id":"CVE-2022-23637","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:k-link:k-box:*:*:*:*:*:*:*:*","versionEndExcluding":"0.33.1","matchCriteriaId":"B79DDF27-7A54-4EBC-817D-1C213C827B4A"}]}]}],"references":[{"url":"https://github.com/k-box/k-box/commit/3bb4df9a4d01aade5bffaa603a514d1a5fabd214","source":"security-advisories@github.com","tags":["Patch","Third Party Advisory"]},{"url":"https://github.com/k-box/k-box/security/advisories/GHSA-wwcw-h4mf-mvxf","source":"security-advisories@github.com","tags":["Third Party Advisory"]},{"url":"https://github.com/k-box/k-box/commit/3bb4df9a4d01aade5bffaa603a514d1a5fabd214","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"]},{"url":"https://github.com/k-box/k-box/security/advisories/GHSA-wwcw-h4mf-mvxf","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}}]}