VYPR
Medium severity6.1NVD Advisory· Published May 10, 2026· Updated May 12, 2026

CVE-2022-50966

CVE-2022-50966

Description

uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the news/manage module. The date_created, date_from, date_to, and created_at parameters in the filter functionality are not properly sanitized, allowing remote attackers to inject malicious scripts via crafted GET requests that execute in victims' browsers.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

uBidAuction 2.0.1 news/manage module has reflected XSS via unsanitized date parameters in GET requests.

Vulnerability

Description

uBidAuction 2.0.1 contains a reflected cross-site scripting (XSS) vulnerability in the news/manage module. The date_created, date_from, date_to, and created_at parameters used in the filter functionality are not properly sanitized before being reflected in the response [2][4]. This allows an attacker to inject arbitrary JavaScript or HTML via crafted GET requests.

Exploitation

Exploitation requires no authentication and can be performed by sending a malicious link to a victim. The attacker crafts a URL containing a JavaScript payload in one of the vulnerable parameters. When the victim clicks the link, the script executes in the context of the victim's browser, making it a classic reflected XSS attack [3].

Impact

Successful exploitation enables an attacker to execute arbitrary JavaScript in the victim's browser, potentially leading to session hijacking, credential theft, or defacement. The CVSS v3 score is 6.1, indicating medium severity.

Mitigation

The vendor has not released a patch as of the latest information. Users are advised to apply input validation and output encoding to these parameters. The vulnerability is disclosed publicly with a working Proof of Concept [3][4].

AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.