Loading HuntDB...

GHSA-4h8r-hw75-4wxx

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

Western Digital My Cloud devices are vulnerable to a cross side scripting vulnerability that can allow a malicious user with elevated privileges access to drives being backed up to construct and inject JavaScript payloads into an authenticated user's browser. As a result, it may be possible to gain control over the authenticated session, steal data, modify settings, or redirect the user to malicious websites. The scope of impact can extend to other components.

Related CVEs

Key Information

GHSA ID
GHSA-4h8r-hw75-4wxx
Published
July 26, 2022 12:00 AM
Last Modified
August 2, 2022 12:00 AM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 13, 2025 6:30 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.