A stored XSS in a kiwi Test Plan can run malicious javascript which could be chained with an HTML injection to perform a UI redressing attack (clickjacking) and an HTML injection which disables the use of the history page.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: @huntrdev

Published: 2022-11-21T00:00:00

Updated: 2024-08-03T01:27:54.514Z

Reserved: 2022-11-21T00:00:00

Link: CVE-2022-4105

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-11-21T20:15:11.870

Modified: 2022-11-23T18:25:10.333

Link: CVE-2022-4105

cve-icon Redhat

No data.