ZeroHour

CVE-2022-22791

CVSS 3.1
5.4 medium
EPSS
<1%p31
Published
()
Modified
Description

SYNEL - eharmony Authenticated Blind & Stored XSS. Inject JS code into the "comments" field could lead to potential stealing of cookies, loading of HTML tags and JS code onto the system.

Vendors
synel
Products
eharmony
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.