CVE-2022-31114

Source
https://cve.org/CVERecord?id=CVE-2022-31114
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-31114.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-31114
Aliases
Published
2026-06-03T14:41:41.395Z
Modified
2026-06-18T03:56:37.439447617Z
Severity
  • 5.1 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N CVSS Calculator
Summary
backpack/crud Vulnerable to Cross-site Scripting
Details

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Versions prior to 5.0.13, 4.1.69, and 4.0.63 are vulnerable to cross-site scripting. An attacker could conduct a targeted phishing campaign, in order to trick users or admins into clicking a malicious link, which under very specific circumstances could give them information or possibly admin access. Versions 5.0.13, 4.1.69, and 4.0.63 patch the issue. As a workaround, manually look inside error views in resources/views/errors and output e($exception->getMessage()) instead of $exception->getMessage().

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-79"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/31xxx/CVE-2022-31114.json"
}
References

Affected packages

Git / github.com/laravel-backpack/crud

Affected ranges

Type
GIT
Repo
https://github.com/laravel-backpack/crud
Events
Database specific
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "5.0.0"
        },
        {
            "fixed": "5.0.13"
        },
        {
            "introduced": "4.0.0"
        },
        {
            "fixed": "4.1.69"
        },
        {
            "introduced": "0"
        },
        {
            "fixed": "4.0.63"
        }
    ]
}

Affected versions

4.*
4.0.0
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.20
4.0.21
4.0.22
4.0.23
4.0.24
4.0.25
4.0.26
4.0.27
4.0.28
4.0.29
4.0.3
4.0.30
4.0.31
4.0.32
4.0.33
4.0.34
4.0.35
4.0.36
4.0.37
4.0.38
4.0.40
4.0.41
4.0.42
4.0.43
4.0.44
4.0.45
4.0.48
4.0.49
4.0.5
4.0.50
4.0.51
4.0.52
4.0.53
4.0.54
4.0.55
4.0.56
4.0.57
4.0.58
4.0.59
4.0.6
4.0.60
4.0.61
4.0.62
4.0.7
4.0.8
4.0.9
4.1.1
4.1.10
4.1.11
4.1.12
4.1.13
4.1.14
4.1.16
4.1.17
4.1.18
4.1.19
4.1.2
4.1.20
4.1.21
4.1.22
4.1.23
4.1.24
4.1.25
4.1.26
4.1.27
4.1.28
4.1.29
4.1.3
4.1.30
4.1.31
4.1.32
4.1.33
4.1.34
4.1.35
4.1.36
4.1.37
4.1.38
4.1.39
4.1.4
4.1.40
4.1.41
4.1.42
4.1.43
4.1.44
4.1.45
4.1.46
4.1.47
4.1.48
4.1.49
4.1.5
4.1.50
4.1.51
4.1.52
4.1.53
4.1.54
4.1.55
4.1.56
4.1.57
4.1.58
4.1.59
4.1.6
4.1.60
4.1.61
4.1.62
4.1.63
4.1.64
4.1.65
4.1.66
4.1.67
4.1.68
4.1.7
4.1.8
4.1.9
5.*
5.0.0
5.0.10
5.0.11
5.0.12
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
v4.*
v4.0.46

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-31114.json"