Description
A stored XSS in a kiwi Test Plan can run malicious javascript which could be chained with an HTML injection to perform a UI redressing attack (clickjacking) and an HTML injection which disables the use of the history page.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-7362 | A stored XSS in a kiwi Test Plan can run malicious javascript which could be chained with an HTML injection to perform a UI redressing attack (clickjacking) and an HTML injection which disables the use of the history page. |
Github GHSA |
GHSA-hf94-8mx5-2vvj | Cross-site Scripting in kiwitcms |
References
History
Mon, 14 Apr 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: @huntrdev
Published:
Updated: 2025-04-14T18:07:53.890Z
Reserved: 2022-11-21T00:00:00.000Z
Link: CVE-2022-4105
Updated: 2024-08-03T01:27:54.514Z
Status : Modified
Published: 2022-11-21T20:15:11.870
Modified: 2024-11-21T07:34:35.557
Link: CVE-2022-4105
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA