CVE-2022-40739: Ragic, Inc. Ragic - Reflected XSS
Ragic report generation page has insufficient filtering for special characters. A remote attacker with general user privilege can inject JavaScript to perform XSS (Reflected Cross-Site Scripting) attack.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ragicto a version that resolves this vulnerability.Fixed in 8/10/2022
Event History
Frequently Asked Questions
What is CVE-2022-40739?
CVE-2022-40739 is a vulnerability that exists in the Ragic report generation page and allows a remote attacker with general user privilege to inject JavaScript and perform a Reflected Cross-Site Scripting (XSS) attack.
How severe is CVE-2022-40739?
CVE-2022-40739 has a severity score of 5.4, which is considered medium.
What is the affected software of CVE-2022-40739?
The affected software of CVE-2022-40739 is Ragic Ragic, up to and including version 2022-06-28.
How can a remote attacker exploit CVE-2022-40739?
A remote attacker with general user privilege can exploit CVE-2022-40739 by injecting JavaScript through the insufficiently filtered special characters on the Ragic report generation page.
Is there a solution for CVE-2022-40739?
To mitigate CVE-2022-40739, users are advised to update to the latest version of Ragic Ragic and apply any recommended patches or fixes provided by the vendor.