ZeroHour

CVE-2022-25229

PoC ×2
CVSS 3.1
5.4 medium
EPSS
<1%p45
Published
()
Modified
Description

Popcorn Time 0.4.7 has a Stored XSS in the 'Movies API Server(s)' field via the 'settings' page. The 'nodeIntegration' configuration is set to on which allows the 'webpage' to use 'NodeJs' features, an attacker can leverage this to run OS commands.

Vendors
popcorn time project
Products
popcorn time
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.