PT-2026-2372 · Testa · Testa
Ashkan Moghaddas
·
Published
2026-01-13
·
Updated
2026-01-14
·
CVE-2022-50896
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Testa version 3.5.1
Description
The software contains a reflected cross-site scripting issue in the
login.php file. Specifically, the redirect parameter is susceptible to malicious script injection. An attacker can craft a specially encoded payload within this parameter to execute arbitrary JavaScript code in a victim’s browser. The vulnerable API endpoint is /login.php and the vulnerable parameter is redirect.Recommendations
Apply any available updates to address the issue in Testa version 3.5.1.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Testa