Lucene search

K
osvGoogleOSV:CVE-2022-22112
HistoryJan 13, 2022 - 9:15 a.m.

CVE-2022-22112

2022-01-1309:15:07
Google
osv.dev
8
daybyday crm
client-side template injection
application security
javascript execution
vulnerability

AI Score

7.5

Confidence

Low

EPSS

0.001

Percentile

21.4%

In DayByDay CRM, versions 1.1 through 2.2.1 (latest) suffer from an application-wide Client-Side Template Injection (CSTI). A low privileged attacker can input template injection payloads in the application at various locations to execute JavaScript on the client browser.

AI Score

7.5

Confidence

Low

EPSS

0.001

Percentile

21.4%

Related for OSV:CVE-2022-22112