VulnerabilityModified
CVE-2022-39054
An unauthenticated remote attacker can inject JavaScript and perform XSS (Reflected Cross-Site Scripting) attack.
MEDIUM 6.1EPSS 0.55%
Does this matter?
Lower severity and a low EPSS score (0.55%). Track it; it rarely justifies an emergency change on its own.
Description
Cowell enterprise travel management system has insufficient filtering for special characters within web URL. An unauthenticated remote attacker can inject JavaScript and perform XSS (Reflected Cross-Site Scripting) attack.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.55% probability · 44th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- cowell enterprise travel management system project/cowell enterprise travel management system
- Source
- twcert@cert.org.tw
References
- https://www.twcert.org.tw/tw/cp-132-6524-74530-1.htmlThird Party Advisory
- https://www.twcert.org.tw/tw/cp-132-6524-74530-1.htmlThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.