Vulnerability Details CVE-2022-40739
Ragic report generation page has insufficient filtering for special characters. A remote attacker with general user privilege can inject JavaScript to perform XSS (Reflected Cross-Site Scripting) attack.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 26.9%
CVSS Severity
CVSS v3 Score 5.4
Products affected by CVE-2022-40739
-
-
cpe:2.3:a:ragic:ragic:2022-06-28