### [CVE-2022-1815](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1815) ![](https://img.shields.io/static/v1?label=Product&message=jgraph%2Fdrawio&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=%3C%2018.1.2%20&color=brighgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-200%20Exposure%20of%20Sensitive%20Information%20to%20an%20Unauthorized%20Actor&color=brighgreen) ### Description Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.1.2. ### POC #### Reference - https://huntr.dev/bounties/6e856a25-9117-47c6-9375-52f78876902f #### Github - https://github.com/ARPSyndicate/kenzer-templates