First published: Wed Jan 04 2023(Updated: )
A vulnerability has been found in fossology and classified as problematic. This vulnerability affects unknown code. The manipulation of the argument sql/VarValue leads to cross site scripting. The attack can be initiated remotely. The patch is identified as 8e0eba001662c7eb35f045b70dd458a4643b4553. It is recommended to apply a patch to fix this issue. VDB-217426 is the identifier assigned to this vulnerability.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fossology | <2023-01-02 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-4875 is classified as a problematic vulnerability affecting the Fossology software.
To fix CVE-2022-4875, apply the patch identified as 8e0eba001662c7eb35f045b70d.
CVE-2022-4875 is a cross-site scripting (XSS) vulnerability caused by manipulation of the sql/VarValue argument.
Yes, an attacker can exploit CVE-2022-4875 remotely.
CVE-2022-4875 affects all versions of Fossology before 2023-01-02.