PT-2022-17169 · Unknown+1 · Beancount/Fava+1

Yagebu

·

Published

2022-07-25

·

Updated

2022-07-27

·

CVE-2022-2523

CVSS v3.1

8.0

High

VectorAV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions beancount/fava versions prior to 1.22.2
Description The issue concerns a Cross-site Scripting (XSS) - Reflected vulnerability. The query string parameter of Fava is vulnerable to reflected cross-site scripting, allowing an attacker to modify any information that the user is able to modify.
Recommendations For versions prior to 1.22.2, update to version 1.22.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the query string parameter to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-2523
GHSA-Q8HG-3VQV-F8V3
PYSEC-2022-240

Affected Products

Debian
Beancount/Fava