uBidAuction 2.0.1 auctions manage Reflected XSS
Vulnerability Description
uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the auctions/manage module. The date_created, date_from, date_to, and created_at parameters in the filter functionality are not properly sanitized, allowing remote attackers to inject malicious scripts via crafted GET requests that execute in victims' browsers.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-50968
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Vulnerability-Lab [Research Team]
References
More from uBidAuction
View All →Affected Vendor
uBidAuction
View all reports →