SYNEL - eharmony Authenticated Blind & Stored XSS. Inject JS code into the "comments" field could lead to potential stealing of cookies, loading of HTML tags and JS code onto the system.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-27934 | SYNEL - eharmony Authenticated Blind & Stored XSS. Inject JS code into the "comments" field could lead to potential stealing of cookies, loading of HTML tags and JS code onto the system. |
Fixes
Solution
A patch was released, Update to eharmony version 11
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.gov.il/en/departments/faq/cve_advisories |
|
History
No history.
Status: PUBLISHED
Assigner: INCD
Published:
Updated: 2024-08-03T03:21:49.200Z
Reserved: 2022-01-07T00:00:00.000Z
Link: CVE-2022-22791
No data.
Status : Modified
Published: 2022-01-28T20:15:12.610
Modified: 2024-11-21T06:47:27.607
Link: CVE-2022-22791
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD