MEDIUM
Cross-site scripting - Reflected in Create Subaccount in neorazorx/facturascripts
Published May 4, 2022
6.1
MEDIUMCVSS 3.1
EPSS 0.87%
Description
Cross-site scripting - Reflected in Create Subaccount in GitHub repository neorazorx/facturascripts prior to 2022.07. This vulnerability can be arbitrarily executed javascript code to steal user'cookie, perform HTTP request, get content of `same origin` page, etc ...
Affected products
-
- Version unspecifiedStatusaffectedConstraints<2022.07
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Neorazorx | Neorazorx/facturascripts | n/a |
|
- < 2022.07
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-4523 Advisory
- https://github.com/advisories/GHSA-m8gv-gvhf-7rhp Advisory
- https://github.com/neorazorx/facturascripts/commit/482c5a82b4d79e7a19614f5a67dc24593046cefd x_refsource_MISCPatchThird Party Advisory
- https://huntr.dev/bounties/4578a690-73e5-4313-840c-ee15e5329741 x_refsource_CONFIRMExploitPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-1571
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-4523 | Advisory | |
| https://github.com/advisories/GHSA-m8gv-gvhf-7rhp | Advisory | |
| https://github.com/neorazorx/facturascripts/commit/482c5a82b4d79e7a19614f5a67dc24593046cefd | x_refsource_MISCPatchThird Party Advisory | |
| https://huntr.dev/bounties/4578a690-73e5-4313-840c-ee15e5329741 | x_refsource_CONFIRMExploitPatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-1571 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner @huntrdev
Published May 4, 2022
Updated Aug 3, 2024
Reserved May 4, 2022
Link CVE-2022-1571
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2022-4523 GHSA-M8GV-GVHF-7RHP Assigner @huntrdev
Published May 4, 2022
Updated Aug 3, 2024
Exploited since n/a
Link EUVD-2022-4523