Description
Wallos 0.9 is vulnerable to Cross Site Scripting (XSS) in all text-based input fields without proper validation, excluding those requiring specific formats like date fields.
References (2)
Core 2
Scores
CVSS v3
4.7
EPSS
0.0013
EPSS Percentile
31.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (1)
wallosapp/wallos
0.9 - 1.2.3
Published
Feb 23, 2024
Tracked Since
Feb 18, 2026