Vulnerability Details CVE-2022-1571
Cross-site scripting - Reflected in Create Subaccount in GitHub repository neorazorx/facturascripts prior to 2022.07. This vulnerability can be arbitrarily executed javascript code to steal user'cookie, perform HTTP request, get content of `same origin` page, etc ...
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 53.3%
CVSS Severity
CVSS v3 Score 9.9
CVSS v2 Score 4.3
Products affected by CVE-2022-1571
-
cpe:2.3:a:facturascripts:facturascripts:-
-
cpe:2.3:a:facturascripts:facturascripts:2018.03
-
cpe:2.3:a:facturascripts:facturascripts:2018.04
-
cpe:2.3:a:facturascripts:facturascripts:2018.05
-
cpe:2.3:a:facturascripts:facturascripts:2018.11
-
cpe:2.3:a:facturascripts:facturascripts:2018.12
-
cpe:2.3:a:facturascripts:facturascripts:2018.13
-
cpe:2.3:a:facturascripts:facturascripts:2018.14
-
cpe:2.3:a:facturascripts:facturascripts:2018.15
-
cpe:2.3:a:facturascripts:facturascripts:2018.16
-
cpe:2.3:a:facturascripts:facturascripts:2020.01
-
cpe:2.3:a:facturascripts:facturascripts:2020.2
-
cpe:2.3:a:facturascripts:facturascripts:2020.3
-
cpe:2.3:a:facturascripts:facturascripts:2020.4
-
cpe:2.3:a:facturascripts:facturascripts:2020.51
-
cpe:2.3:a:facturascripts:facturascripts:2020.61
-
cpe:2.3:a:facturascripts:facturascripts:2020.71
-
cpe:2.3:a:facturascripts:facturascripts:2020.80
-
cpe:2.3:a:facturascripts:facturascripts:2021
-
cpe:2.3:a:facturascripts:facturascripts:2021.1
-
cpe:2.3:a:facturascripts:facturascripts:2021.2
-
cpe:2.3:a:facturascripts:facturascripts:2021.4
-
cpe:2.3:a:facturascripts:facturascripts:2021.51
-
cpe:2.3:a:facturascripts:facturascripts:2021.71
-
cpe:2.3:a:facturascripts:facturascripts:2021.81
-
cpe:2.3:a:facturascripts:facturascripts:2022.06
-
cpe:2.3:a:facturascripts:facturascripts:2022.2
-
cpe:2.3:a:facturascripts:facturascripts:2022.4