Headline
GHSA-xrf4-39fm-j5f2: Fava time and filter parameters vulnerable to reflected XSS before v1.22
The time and filter parameters in Fava prior to v1.22 are vulnerable to reflected cross-site scripting due to the lack of escaping of error messages which contained the parameters in verbatim.
Fava time and filter parameters vulnerable to reflected XSS before v1.22
Moderate severity GitHub Reviewed Published Jul 26, 2022 • Updated Aug 6, 2022
Related news
CVE-2022-2514: Cross-site Scripting (XSS) - Reflected in fava
The time and filter parameters in Fava prior to v1.22 are vulnerable to reflected XSS due to the lack of escaping of error messages which contained the parameters in verbatim.