CVE-2022-4523
Summary
| CVE | CVE-2022-4523 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-12-15 21:15:00 UTC |
| Updated | 2024-01-25 20:40:00 UTC |
| Description | A vulnerability, which was classified as problematic, has been found in vexim2. This issue affects some unknown processing. The manipulation leads to cross site scripting. The attack may be initiated remotely. The name of the patch is 21c0a60d12e9d587f905cd084b2c70f9b1592065. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-215903. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Virtual Exim Project | Virtual Exim 2 | All | All | All | All |
| Application | Virtual Exim Project | Virtual Exim 2 | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2022-4523 | vexim2 cross site scripting (ID 274) | N/A | vuldb.com | |
| Merge pull request #274 from rimas-kudelis/xss-prevention · vexim/vexim2@21c0a60 · GitHub | N/A | github.com | |
| Use `htmlspecialchars()` to escape user-provided vars before output by rimas-kudelis · Pull Request #274 · vexim/vexim2 · GitHub | N/A | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.