Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Oxidized Web Project Subscribe
Filtered by product Oxidized Web
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-25088 1 Oxidized Web Project 1 Oxidized Web 2023-01-05 N/A 5.4 MEDIUM
A vulnerability was found in ytti Oxidized Web. It has been classified as problematic. Affected is an unknown function of the file lib/oxidized/web/views/conf_search.haml. The manipulation of the argument to_research leads to cross site scripting. It is possible to launch the attack remotely. The name of the patch is 55ab9bdc68b03ebce9280b8746ef31d7fdedcc45. It is recommended to apply a patch to fix this issue. VDB-216870 is the identifier assigned to this vulnerability.