CVE-2022-1571: Cross-site scripting - Reflected in Create Subaccount in neorazorx/facturascripts
Cross-site scripting - Reflected in Create Subaccount in GitHub repository neorazorx/facturascripts prior to 2022.07. This vulnerability can be arbitrarily executed javascript code to steal user'cookie, perform HTTP request, get content of same origin page, etc ...
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-1571?
CVE-2022-1571 is a cross-site scripting vulnerability that exists in the Create Subaccount feature of the GitHub repository neorazorx/facturascripts prior to version 2022.07.
How severe is CVE-2022-1571?
CVE-2022-1571 has a severity rating of critical with a CVSS score of 6.1.
What can an attacker do with CVE-2022-1571?
An attacker can exploit CVE-2022-1571 to execute arbitrary JavaScript code, potentially stealing user's cookies, performing unauthorized HTTP requests, or accessing the content of same-origin pages.
How can I fix CVE-2022-1571?
To fix CVE-2022-1571, it is recommended to update the affected software to version 2022.07 or later.
Where can I find more information about CVE-2022-1571?
You can find more information about CVE-2022-1571 in the GitHub commit (https://github.com/neorazorx/facturascripts/commit/482c5a82b4d79e7a19614f5a67dc24593046cefd) and the Huntr.dev bounty report (https://huntr.dev/bounties/4578a690-73e5-4313-840c-ee15e5329741).