Lucene search

K
cveMitreCVE-2022-35163
HistoryAug 05, 2022 - 9:15 p.m.

CVE-2022-35163

2022-08-0521:15:09
CWE-79
mitre
web.nvd.nist.gov
37
3
cve-2022-35163
online job search system
xss vulnerability
nvd

CVSS3

4.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

24.8%

Complete Online Job Search System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the U_NAME parameter at /category/controller.php?action=edit.

Affected configurations

Nvd
Node
complete_online_job_search_system_projectcomplete_online_job_search_systemMatch1.0
VendorProductVersionCPE
complete_online_job_search_system_projectcomplete_online_job_search_system1.0cpe:2.3:a:complete_online_job_search_system_project:complete_online_job_search_system:1.0:*:*:*:*:*:*:*

Social References

More

CVSS3

4.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

24.8%

Related for CVE-2022-35163