Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-xrf4-39fm-j5f2: Fava time and filter parameters vulnerable to reflected XSS before v1.22

The time and filter parameters in Fava prior to v1.22 are vulnerable to reflected cross-site scripting due to the lack of escaping of error messages which contained the parameters in verbatim.

ghsa
#xss#git

Fava time and filter parameters vulnerable to reflected XSS before v1.22

Moderate severity GitHub Reviewed Published Jul 26, 2022 • Updated Aug 6, 2022

Related news

CVE-2022-2514: Cross-site Scripting (XSS) - Reflected in fava

The time and filter parameters in Fava prior to v1.22 are vulnerable to reflected XSS due to the lack of escaping of error messages which contained the parameters in verbatim.