CVE-2022-32177
Estado: ModificadaCrítica (9)—
In "Gin-Vue-Admin", versions v2.5.1 through v2.5.3beta are vulnerable to Unrestricted File Upload that leads to execution of javascript code, through the 'Normal Upload' functionality to the Media Library. When an admin user views the uploaded file, a low privilege attacker will get access to the admin’s cookie leading to account takeover.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
- Puntuación base: 9
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.04%
- Percentil entre todas las CVEs puntuadas: 63
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-434
- CWE-434
Referencias
- https://github.com/flipped-aurora/gin-vue-admin/blob/v2.5.3beta/web/src/components/upload/common.vue#L29-L37
- https://www.mend.io/vulnerability-database/CVE-2022-32177
- https://github.com/flipped-aurora/gin-vue-admin/blob/v2.5.3beta/web/src/components/upload/common.vue#L29-L37
- https://www.mend.io/vulnerability-database/CVE-2022-32177
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-32177",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2022-32177",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2025-05-14T15:18:31.840168Z"
}
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 9,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 6,
"exploitabilityScore": 2.3
},
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 9,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 6,
"exploitabilityScore": 2.3
}
]
},
"affected": [
{
"source": "vulnerabilitylab@mend.io",
"affectedData": [
{
"vendor": "gin-vue-admin",
"product": "gin-vue-admin",
"versions": [
{
"status": "affected",
"version": "v2.5.1",
"lessThan": "unspecified",
"versionType": "custom"
},
{
"status": "affected",
"version": "unspecified",
"versionType": "custom",
"lessThanOrEqual": "v2.5.3beta"
}
]
}
]
}
],
"published": "2022-10-14T07:15:09.057",
"references": [
{
"url": "https://github.com/flipped-aurora/gin-vue-admin/blob/v2.5.3beta/web/src/components/upload/common.vue#L29-L37",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "vulnerabilitylab@mend.io"
},
{
"url": "https://www.mend.io/vulnerability-database/CVE-2022-32177",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "vulnerabilitylab@mend.io"
},
{
"url": "https://github.com/flipped-aurora/gin-vue-admin/blob/v2.5.3beta/web/src/components/upload/common.vue#L29-L37",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.mend.io/vulnerability-database/CVE-2022-32177",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "vulnerabilitylab@mend.io",
"description": [
{
"lang": "en",
"value": "CWE-434"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-434"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In \"Gin-Vue-Admin\", versions v2.5.1 through v2.5.3beta are vulnerable to Unrestricted File Upload that leads to execution of javascript code, through the 'Normal Upload' functionality to the Media Library. When an admin user views the uploaded file, a low privilege attacker will get access to the admin’s cookie leading to account takeover."
},
{
"lang": "es",
"value": "En \"Gin-Vue-Admin\", versiones v2.5.1 hasta v2.5.3beta, son vulnerables a una subida de archivos sin restricciones que conlleva a una ejecución de código javascript, mediante la funcionalidad \"Normal Upload\" a la biblioteca de medios. Cuando un usuario administrador visualiza el archivo subido, un atacante de bajo privilegio obtendrá acceso a la cookie del administrador conllevando a una toma de la cuenta"
}
],
"lastModified": "2026-06-17T04:46:49.583",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:gin-vue-admin_project:gin-vue-admin:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0E0062A1-B2B9-42AB-8E46-8B4B1DCE71D8",
"versionEndIncluding": "2.5.2",
"versionStartIncluding": "2.5.1"
},
{
"criteria": "cpe:2.3:a:gin-vue-admin_project:gin-vue-admin:2.5.3:beta:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6C134734-016F-4CF0-BFF8-EBFC029AFDCD"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "vulnerabilitylab@mend.io"
}