PT-2026-39490 · Ubidauction · Ubidauction

Published

2026-05-10

·

Updated

2026-05-10

·

CVE-2022-50965

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the posts/manage module. The date created, date from, date to, and created at parameters in the filter functionality are not properly sanitized, allowing remote attackers to inject malicious scripts via crafted GET requests that execute in victims' browsers.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-50965

Affected Products

Ubidauction