CVE-2022-2514
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD
Description
The time and filter parameters in Fava prior to v1.22 are vulnerable to reflected XSS due to the lack of escaping of error messages which contained the parameters in verbatim.
Affected (1)
Products: Fava Project: Fava
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.22 |
References (4)
Source: security@huntr.dev
PatchThird Party Advisory
Source: security@huntr.dev
ExploitPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatchThird Party Advisory
Timeline
No history available yet.