CVE-2022-2514

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
25/07/2022
Last modified:
27/07/2022

Description

The time and filter parameters in Fava prior to v1.22 are vulnerable to reflected XSS due to the lack of escaping of error messages which contained the parameters in verbatim.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fava_project:fava:*:*:*:*:*:*:*:* 1.22 (excluding)