CVE-2022-0121

Plain English Summary

AI-powered analysis for quick understanding

This vulnerability allows an attacker to inject malicious scripts into web pages viewed by other users, potentially stealing sensitive information or taking control of their accounts. It affects versions of Hoppscotch before 2.1.1, so users need to update to the latest version to protect themselves.

Technical Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hoppscotch hoppscotch/hoppscotch.This issue affects hoppscotch/hoppscotch before 2.1.1.

CVSS Vector Analysis

Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionRequired
Confidentiality ImpactHigh
Integrity ImpactHigh
Availability ImpactHigh
ScopeUnchanged

Vector String

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Exploit Resources

Search for proof-of-concept code and exploit modules

Official References

Est. Bounty
$3,105($1K-$5K)
Vendor Response
Grade FPatched in 1510 days

Quick Information

Published

Jan 6, 2022

over 4 years ago

Last Modified

Feb 24, 2026

about 1 month ago

Vendor

hoppscotch

Product

hoppscotch