CVE-2022-2829Cross-site Scripting in Yetiforcecrm

Severity
5.4MEDIUMNVD
EPSS
0.4%
top 40.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 23
Latest updateAug 24

Description

Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-gj5j-mwf9-rqv9: Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 62022-08-24
CVEList
Cross-site Scripting (XSS) - Stored in yetiforcecompany/yetiforcecrm2022-08-23
CVE-2022-2829 — Cross-site Scripting in Yetiforcecrm | cvebase