github.com
https://github.com/notrinos/notrinoserp CVE-2022-2871
MEDIUM
Cross-site Scripting (XSS) - Stored in notrinos/notrinoserp
Record summary
CVE-2022-2871 has a selected CVSS score of 5.4 (medium).
Description
Cross-site Scripting (XSS) - Stored in GitHub repository notrinos/notrinoserp prior to 0.7.
Description source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
notrinos/notrinoserpBrowse notrinos / notrinos/notrinoserp | CVE List | Before 0.7 | affected |
notrinos/notrinos-erpBrowse Packagist / notrinos/notrinos-erp | GitHub Advisory | Through 0.7 | affected |
References
4github.com
https://github.com/notrinos/notrinoserp/commit/0362778f4f678156c22a009094225823df8a4760 huntr.devConfirmation
https://huntr.dev/bounties/61126c07-22ac-4961-a198-1aa33060b373 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-2871