Cross site scripting (XSS) vulnerability in kfm through 1.4.7 via crafted GET request to /kfm/index.php.
References
Link | Resource |
---|---|
https://cxsecurity.com/issue/WLB-2022090057 | Exploit Third Party Advisory |
https://code.google.com/archive/p/kfm/downloads | Product |
Configurations
Information
Published : 2022-09-23 11:15
Updated : 2022-09-27 05:14
NVD link : CVE-2022-40359
Mitre link : CVE-2022-40359
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
kfm_project
- kfm