Junglewise Threat Intelligence

CVE-2022-30289: PYSEC-2022-43185 - A stored Cross-site Scripting (XSS) vulnerability was identified in the Data Import functionality of OpenCTI through 5.2.4. An attacker can

CVE-2022-30289 · Severity: low · CVSS 3.1 · Published 2022-07-05

Technologies: pycti (PyPI). Vendors: PyPI.

Executive brief

A stored Cross-site Scripting (XSS) vulnerability was identified in the Data Import functionality of OpenCTI through 5.2.4. An attacker can abuse the vulnerability to upload a malicious file that will then be executed by a victim when they open the file location.

Affected products

  • PyPI pycti

Related threats