5.4
CVSSv3

CVE-2022-39172

Published: 30/10/2023 Updated: 07/11/2023
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 0

Vulnerability Summary

A stored XSS in the process overview (bersicht zugewiesener Vorgaenge) in mbsupport openVIVA c2 20220101 allows a remote, authenticated, low-privileged malicious user to execute arbitrary code in the victim's browser via name field of a process.

Vulnerable Product Search on Vulmon Subscribe to Product

viva-project openviva

Exploits

openVIVA c2 suffers from a persistent cross site scripting vulnerability Versions prior to 20220801 are affected ...