Cross-Site Scripting Vulnerability in Expense Tracker by Cyb3r N3rd
CVE-2022-45033

5.4MEDIUM

Key Information:

Vendor

Oretnom23

Vendor
CVE Published:
15 December 2022

What is CVE-2022-45033?

A cross-site scripting vulnerability in Expense Tracker version 1.0 enables attackers to inject and execute arbitrary web scripts or HTML. This flaw arises due to inadequate input validation in the Chat text field, allowing malicious users to exploit the system by creating crafted payloads that can target unsuspecting users. Successful exploitation could lead to session hijacking, data theft, or further attacks on the web application and its users.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.