CVE-2022-1682

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-1682
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-1682.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-1682
Aliases
Published
2022-05-12T08:15:17Z
Modified
2025-11-28T02:35:46.000443Z
Severity
  • 9.4 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L CVSS Calculator
Summary
Reflected Xss using url based payload in neorazorx/facturascripts
Details

Reflected Xss using url based payload in GitHub repository neorazorx/facturascripts prior to 2022.07. Xss can use to steal user's cookies which lead to Account takeover or do any malicious activity in victim's browser

Database specific
{
    "cna_assigner": "@huntrdev",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/1xxx/CVE-2022-1682.json",
    "cwe_ids": [
        "CWE-79"
    ]
}
References

Affected packages

Git / github.com/neorazorx/facturascripts

Affected ranges

Type
GIT
Repo
https://github.com/neorazorx/facturascripts
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

2018.*

2018.03
2018.04
2018.05
2018.11

v2018.*

v2018.12
v2018.13
v2018.14
v2018.15
v2018.16

v2020.*

v2020.01
v2020.2
v2020.3
v2020.4
v2020.51
v2020.61
v2020.71
v2020.80

Other

v2021

v2021.*

v2021.1
v2021.2
v2021.4
v2021.51
v2021.71
v2021.81

v2022.*

v2022.06