CVE-2022-0157 — Cross-site Scripting in Phoronix-test-suite
Severity
5.4MEDIUMNVD
EPSS
0.4%
top 39.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 10
Latest updateFeb 11
Description
phoronix-test-suite is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7
Affected Packages2 packages
Also affects: Fedora 34, 35
Patches
🔴Vulnerability Details
2GHSA▶
GHSA-c5r9-p98m-5773: phoronix-test-suite is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')↗2022-02-11
OSV▶
CVE-2022-0157: phoronix-test-suite is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')↗2022-01-10