CVE-2022-40739

Publication date

2022-10-31 06:40:40

Family

twcert

State

PUBLISHED

Description

Ragic report generation page has insufficient filtering for special characters. A remote attacker with general user privilege can inject JavaScript to perform XSS (Reflected Cross-Site Scripting) attack.