CVE-2022-23861

Multiple Stored Cross-Site Scripting vulnerabilities were discovered in Y Soft SAFEQ 6 Build 53. Multiple fields in the YSoft SafeQ web application can be used to inject malicious inputs that, due to a lack of output sanitization, result in the execution of arbitrary JS code. These fields can be leveraged to perform XSS attacks on legitimate users accessing the SafeQ web interface.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ysoft:safeq:6.0:build53:*:*:*:*:*:*

History

No history.

Information

Published : 2024-10-22 16:15

Updated : 2024-11-01 14:19


NVD link : CVE-2022-23861

Mitre link : CVE-2022-23861

CVE.ORG link : CVE-2022-23861


JSON object : View

Products Affected

ysoft

  • safeq
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')