Beveiligingsadvies

CVE-2022-2514

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2022-07-25 13:42:34
Laatst bijgewerkt 2024-08-03 00:39:08
Toegewezen door @huntrdev
CVSS-score 8.0
Status PUBLISHED

Beschrijving

The time and filter parameters in Fava prior to v1.22 are vulnerable to reflected XSS due to the lack of escaping of error messages which contained the parameters in verbatim.