CVE-2022-4347

LOW

beetl-bbs - Cross-Site Scripting via User Argument in WebUtils.java

Title source: llm
STIX 2.1

Description

A vulnerability was found in xiandafu beetl-bbs. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file WebUtils.java. The manipulation of the argument user leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-215107.

References (2)

Core 2
Core References
Exploit, Issue Tracking, Third Party Advisory
https://gitee.com/xiandafu/beetl-bbs/issues/I5XD5O
Third Party Advisory
https://vuldb.com/?id.215107

Scores

CVSS v3 3.5
EPSS 0.0019
EPSS Percentile 40.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-707
Status published
Products (1)
beetl-bbs_project/beetl-bbs
Published Dec 08, 2022
Tracked Since Feb 18, 2026