SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-1290

Stored XSS in "Name", "Group Name" & "Title" in GitHub repository polonel/trudesk prior to v1.2.0.

MEDIUM 5.4EPSS 1.65%

Does this matter?

Lower severity and a low EPSS score (1.65%). Track it; it rarely justifies an emergency change on its own.

Description

Stored XSS in "Name", "Group Name" & "Title" in GitHub repository polonel/trudesk prior to v1.2.0. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive data exposure, and worse.

CVSS 3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS
1.65% probability · 75th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
trudesk project/trudesk
Source
security@huntr.dev

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.