CVE-2022-39054

Publication date

2022-09-28 03:25:41

Family

twcert

State

PUBLISHED

Description

Cowell enterprise travel management system has insufficient filtering for special characters within web URL. An unauthenticated remote attacker can inject JavaScript and perform XSS (Reflected Cross-Site Scripting) attack.