VulnerabilityModified
CVE-2022-4593
A vulnerability was found in retra-system.
MEDIUM 6.1EPSS 0.39%
Does this matter?
Lower severity and a low EPSS score (0.39%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability was found in retra-system. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The name of the patch is a6d94ab88f4a6f631a14c59b72461140fb57ae1f. It is recommended to apply a patch to fix this issue. VDB-216186 is the identifier assigned to this vulnerability.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.39% probability · 32th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-707, CWE-79
- Affected
- retra-system project/retra-system
- Source
- cna@vuldb.com
References
- https://github.com/retra/retra-system/commit/a6d94ab88f4a6f631a14c59b72461140fb57ae1fPatch, Third Party Advisory
- https://vuldb.com/?id.216186Permissions Required, Third Party Advisory
- https://github.com/retra/retra-system/commit/a6d94ab88f4a6f631a14c59b72461140fb57ae1fPatch, Third Party Advisory
- https://vuldb.com/?id.216186Permissions Required, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.