ZeroHour

CVE-2022-2514

PoC
CVSS 3.1
6.1 medium
EPSS
<1%p56
Published
()
Modified
Description

The time and filter parameters in Fava prior to v1.22 are vulnerable to reflected XSS due to the lack of escaping of error messages which contained the parameters in verbatim.

Vendors
fava project
Products
fava
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.