CVE-2022-3255
Estado: ModificadaMedia (4.8)—
Si un atacante puede controlar un script que es ejecutado en el navegador de la víctima, entonces puede comprometer completamente a ese usuario. Entre otras cosas, el atacante puede llevar a cabo cualquier acción dentro de la aplicación que el usuario pueda realizar. Visualizar cualquier información que el usuario es capaz de observar. Modificar cualquier información que el usuario es capaz de cambiar. Iniciar interacciones con otros usuarios de la aplicación, incluyendo ataques maliciosos, que parecerán originados por el usuario víctima inicial
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
- Puntuación base: 4.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.82%
- Percentil entre todas las CVEs puntuadas: 56
- Fecha de la puntuación: 9/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-79
- CWE-79
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-3255",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2022-3255",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2025-05-28T15:21:24.868395Z"
}
}
],
"cvssMetricV30": [
{
"type": "Secondary",
"source": "security@huntr.dev",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 6.8,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 0.9
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 4.8,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "HIGH",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 1.7
}
]
},
"affected": [
{
"source": "security@huntr.dev",
"affectedData": [
{
"vendor": "pimcore",
"product": "pimcore/pimcore",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "10.5.7",
"versionType": "custom"
}
]
}
]
}
],
"published": "2022-09-21T13:15:09.460",
"references": [
{
"url": "https://github.com/pimcore/pimcore/commit/1e916e7d668c9e47b217e20cc0ea4812f466201b",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "security@huntr.dev"
},
{
"url": "https://huntr.dev/bounties/0ea45cf9-b256-454c-9031-2435294c0902",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "security@huntr.dev"
},
{
"url": "https://github.com/pimcore/pimcore/commit/1e916e7d668c9e47b217e20cc0ea4812f466201b",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://huntr.dev/bounties/0ea45cf9-b256-454c-9031-2435294c0902",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security@huntr.dev",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "If an attacker can control a script that is executed in the victim's browser, then they can typically fully compromise that user. Amongst other things, the attacker can: Perform any action within the application that the user can perform. View any information that the user is able to view. Modify any information that the user is able to modify. Initiate interactions with other application users, including malicious attacks, that will appear to originate from the initial victim user."
},
{
"lang": "es",
"value": "Si un atacante puede controlar un script que es ejecutado en el navegador de la víctima, entonces puede comprometer completamente a ese usuario. Entre otras cosas, el atacante puede llevar a cabo cualquier acción dentro de la aplicación que el usuario pueda realizar. Visualizar cualquier información que el usuario es capaz de observar. Modificar cualquier información que el usuario es capaz de cambiar. Iniciar interacciones con otros usuarios de la aplicación, incluyendo ataques maliciosos, que parecerán originados por el usuario víctima inicial"
}
],
"lastModified": "2026-06-17T04:59:10.023",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:pimcore:pimcore:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D667A563-6212-47F2-B7BE-2DBDFFCEF2E9",
"versionEndExcluding": "10.5.7"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@huntr.dev"
}