CVE-2022-4960
cloudfavorites favorites-web Nickname cross site scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
A vulnerability, which was classified as problematic, has been found in cloudfavorites favorites-web 1.3.0. Affected by this issue is some unknown functionality of the component Nickname Handler. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-250238 is the identifier assigned to this vulnerability.
Una vulnerabilidad fue encontrada en cloudfavorites-web 1.3.0 y clasificada como problemática. Una función desconocida del componente Nickname Handler es afectada por esta vulnerabilidad. La manipulación conduce a cross site scripting. El ataque puede lanzarse de forma remota. La explotación ha sido divulgada al público y puede utilizarse. VDB-250238 es el identificador asignado a esta vulnerabilidad.
Eine problematische Schwachstelle wurde in cloudfavorites favorites-web 1.3.0 entdeckt. Betroffen davon ist ein unbekannter Prozess der Komponente Nickname Handler. Durch Beeinflussen mit unbekannten Daten kann eine cross site scripting-Schwachstelle ausgenutzt werden. Die Umsetzung des Angriffs kann dabei über das Netzwerk erfolgen. Der Exploit steht zur öffentlichen Verfügung.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2024-01-10 CVE Reserved
- 2024-01-12 CVE Published
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- 2024-12-12 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://vuldb.com/?id.250238 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://github.com/cloudfavorites/favorites-web/issues/127 | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Favorites-web Project Search vendor "Favorites-web Project" | Favorites-web Search vendor "Favorites-web Project" for product "Favorites-web" | 1.3.0 Search vendor "Favorites-web Project" for product "Favorites-web" and version "1.3.0" | - |
Affected
|