CVE-2022-23861

Multiple Stored Cross-Site Scripting vulnerabilities were discovered in Y Soft SAFEQ 6 Build 53. Multiple fields in the YSoft SafeQ web application can be used to inject malicious inputs that, due to a lack of output sanitization, result in the execution of arbitrary JS code. These fields can be leveraged to perform XSS attacks on legitimate users accessing the SafeQ web interface.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ysoft:safeq:6.0:build53:*:*:*:*:*:*

History

01 Nov 2024, 14:19

Type Values Removed Values Added
CPE cpe:2.3:a:ysoft:safeq:6.0:build_53:*:*:*:*:*:* cpe:2.3:a:ysoft:safeq:6.0:build53:*:*:*:*:*:*

30 Oct 2024, 15:49

Type Values Removed Values Added
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
First Time Ysoft
Ysoft safeq
CPE cpe:2.3:a:ysoft:safeq:6.0:build_53:*:*:*:*:*:*
References () https://github.com/mbadanoiu/CVE-2022-23861 - () https://github.com/mbadanoiu/CVE-2022-23861 - Exploit, Third Party Advisory
References () https://ysoft.com - () https://ysoft.com - Product
References () https://github.com/mbadanoiu/CVE-2022-23861/blob/main/SafeQ%20-%20CVE-2022-23861.pdf - () https://github.com/mbadanoiu/CVE-2022-23861/blob/main/SafeQ%20-%20CVE-2022-23861.pdf - Exploit

22 Oct 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-22 16:15

Updated : 2024-11-01 14:19


NVD link : CVE-2022-23861

Mitre link : CVE-2022-23861


JSON object : View

Products Affected

ysoft

  • safeq
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')