CVE-2022-39172
30.10.2023, 22:15
A stored XSS in the process overview (bersicht zugewiesener Vorgaenge) in mbsupport openVIVA c2 20220101 allows a remote, authenticated, low-privileged attacker to execute arbitrary code in the victim's browser via name field of a process.
Vendor | Product | Version |
---|---|---|
viva-project | openviva | 𝑥 < 2022-08-01 |
𝑥
= Vulnerable software versions