CVE-2022-1997: Cross-site Scripting (XSS) - Stored in francoisjacquet/rosariosis
Published Jun 6, 2022
·Updated
Cross-site Scripting (XSS) - Stored in GitHub repository francoisjacquet/rosariosis prior to 9.0.
Affected Software
1 affected component
RosarioSIS RosarioSIS<9.0
Remediation
Event History
Jun 6, 2022
CVE Published
via MITRE·10:10 AM
Data Sourced
via MITRE·10:10 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-1997?
The severity of CVE-2022-1997 is high with a CVSS score of 5.4.
2
How do I fix CVE-2022-1997?
To fix CVE-2022-1997, update the GitHub repository francoisjacquet/rosariosis to version 9.0 or above.
3
What is the affected software for CVE-2022-1997?
The affected software for CVE-2022-1997 is Rosariosis version up to 9.0.
4
What is the CWE for CVE-2022-1997?
The CWE for CVE-2022-1997 is CWE-79 (Improper Neutralization of Input During Web Page Generation)
5
Where can I find more information about CVE-2022-1997?
You can find more information about CVE-2022-1997 on the GitHub page for repository francoisjacquet/rosariosis and the huntr.dev bounty page.