Description
An HTML injection vulnerability exists in CERT/CC VINCE software prior to 1.50.4. An authenticated attacker can inject arbitrary HTML via form using the "Product Affected" field.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-43546 | An HTML injection vulnerability exists in CERT/CC VINCE software prior to 1.50.4. An authenticated attacker can inject arbitrary HTML via form using the "Product Affected" field. |
References
| Link | Providers |
|---|---|
| https://github.com/CERTCC/VINCE/issues?q=label%3Asecurity |
|
History
No history.
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2024-08-03T12:14:39.964Z
Reserved: 2022-09-08T00:00:00.000Z
Link: CVE-2022-40248
No data.
Status : Modified
Published: 2022-10-10T20:15:09.727
Modified: 2024-11-21T07:21:08.253
Link: CVE-2022-40248
No data.
OpenCVE Enrichment
No data.
EUVD