Vulnerability Details CVE-2022-48612
A Universal Cross Site Scripting (UXSS) vulnerability in ClassLink OneClick Extension through 10.7 allows remote attackers to inject JavaScript into any webpage, because a regular expression (validating whether a URL is controlled by ClassLink) is not present in all applicable places.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 31.2%
CVSS Severity
CVSS v3 Score 6.1
Products affected by CVE-2022-48612
-
cpe:2.3:a:classlink:oneclick:-
-
cpe:2.3:a:classlink:oneclick:10.7