{"id":"CVE-2022-3783","aliases":["GHSA-vrv9-3x3w-ffxw"],"url":"https://o3.security/vulnerability/CVE-2022-3783","summary":"node-red-dashboard ui_text Format ui-component-ctrl.js cross site scripting","details":"A vulnerability, which was classified as problematic, has been found in node-red-dashboard. This issue affects some unknown processing of the file components/ui-component/ui-component-ctrl.js of the component ui_text Format Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The name of the patch is 9305d1a82f19b235dfad24a7d1dd4ed244db7743. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-212555.","published":"2022-10-31T00:00:00Z","modified":"2026-07-15T01:49:14.530273369Z","cvss":{"score":3.5,"severity":"LOW","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"npm","name":"node-red-dashboard","fixedVersion":"3.2.0"}],"fix":{"url":"https://github.com/node-red/node-red-dashboard/commit/9305d1a82f19b235dfad24a7d1dd4ed244db7743","label":"node-red/node-red-dashboard@9305d1a"},"references":[{"type":"WEB","url":"https://vuldb.com/?id.212555"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/3xxx/CVE-2022-3783.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-3783"},{"type":"REPORT","url":"https://github.com/node-red/node-red-dashboard/issues/772"},{"type":"FIX","url":"https://github.com/node-red/node-red-dashboard/commit/9305d1a82f19b235dfad24a7d1dd4ed244db7743"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:14.530273369Z"}}