Multiple Stored Cross-Site Scripting vulnerabilities were discovered in Y Soft SAFEQ 6 Build 53. Multiple fields in the YSoft SafeQ web application can be used to inject malicious inputs that, due to a lack of output sanitization, result in the execution of arbitrary JS code. These fields can be leveraged to perform XSS attacks on legitimate users accessing the SafeQ web interface.
References
Link | Resource |
---|---|
https://github.com/mbadanoiu/CVE-2022-23861 | Exploit Third Party Advisory |
https://github.com/mbadanoiu/CVE-2022-23861/blob/main/SafeQ%20-%20CVE-2022-23861.pdf | Exploit |
https://ysoft.com | Product |
Configurations
History
30 Oct 2024, 15:49
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:ysoft:safeq:6.0:build_53:*:*:*:*:*:* | |
References | () https://github.com/mbadanoiu/CVE-2022-23861 - Exploit, Third Party Advisory | |
References | () https://github.com/mbadanoiu/CVE-2022-23861/blob/main/SafeQ%20-%20CVE-2022-23861.pdf - Exploit | |
References | () https://ysoft.com - Product | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
First Time |
Ysoft safeq
Ysoft |
23 Oct 2024, 15:12
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
22 Oct 2024, 19:35
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-79 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.1 |
22 Oct 2024, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-10-22 16:15
Updated : 2024-10-30 15:49
NVD link : CVE-2022-23861
Mitre link : CVE-2022-23861
CVE.ORG link : CVE-2022-23861
JSON object : View
Products Affected
ysoft
- safeq
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')