Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-48612
HistoryOct 16, 2023 - 12:15 a.m.

Cross site scripting

2023-10-1600:15:00
PRIOn knowledge base
www.prio-n.com
7
cross site scripting
universal
injection
javascript
remote attack
regular expression
validation
classlink

0.001 Low

EPSS

Percentile

27.8%

A Universal Cross Site Scripting (UXSS) vulnerability in ClassLink OneClick Extension through 10.7 allows remote attackers to inject JavaScript into any webpage, because a regular expression (validating whether a URL is controlled by ClassLink) is not present in all applicable places.

CPENameOperatorVersion
oneclickle10.7

0.001 Low

EPSS

Percentile

27.8%

Related for PRION:CVE-2022-48612