The application was vulnerable to an authenticated Stored Cross-Site Scripting (XSS) in the user profile data fields, which could be leveraged to escalate privileges within and compromise any account that views their user profile.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-43585 | The application was vulnerable to an authenticated Stored Cross-Site Scripting (XSS) in the user profile data fields, which could be leveraged to escalate privileges within and compromise any account that views their user profile. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 06 May 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: TML
Published:
Updated: 2025-05-06T19:22:35.531Z
Reserved: 2022-09-08T00:00:00.000Z
Link: CVE-2022-40288
Updated: 2024-08-03T12:14:39.966Z
Status : Modified
Published: 2022-10-31T21:15:12.790
Modified: 2025-05-06T20:15:23.700
Link: CVE-2022-40288
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD