The time and filter parameters in Fava prior to v1.22 are vulnerable to reflected XSS due to the lack of escaping of error messages which contained the parameters in verbatim.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-0100 | The time and filter parameters in Fava prior to v1.22 are vulnerable to reflected XSS due to the lack of escaping of error messages which contained the parameters in verbatim. |
Github GHSA |
GHSA-xrf4-39fm-j5f2 | Fava time and filter parameters vulnerable to reflected Cross-site Scripting |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: @huntrdev
Published:
Updated: 2024-08-03T00:39:08.013Z
Reserved: 2022-07-22T00:00:00
Link: CVE-2022-2514
No data.
Status : Modified
Published: 2022-07-25T14:15:10.873
Modified: 2024-11-21T07:01:09.150
Link: CVE-2022-2514
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA