Cross-Site Scripting Vulnerabilities in Hubzilla by Zotlabs
CVE-2022-27258

6.1MEDIUM

Key Information:

Vendor

Hubzilla

Status
Vendor
CVE Published:
15 April 2022

What is CVE-2022-27258?

Multiple Cross-Site Scripting (XSS) vulnerabilities in Hubzilla versions 7.0.3 and earlier allow remote attackers to inject arbitrary web scripts or HTML by manipulating the rpath parameter. This could lead to unauthorized actions being performed on behalf of unsuspecting users, compromising the integrity and security of the application.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.