CVE-2022-2514
25.07.2022, 14:15
The time and filter parameters in Fava prior to v1.22 are vulnerable to reflected XSS due to the lack of escaping of error messages which contained the parameters in verbatim.
| Vendor | Product | Version |
|---|---|---|
| fava_project | fava | 𝑥 < 1.22 |
𝑥
= Vulnerable software versions
Ubuntu Releases