VYPR

Force UserDefault page

by U Office

CVEs (1)

  • CVE-2022-39026MedOct 31, 2022
    risk 0.35cvss 5.4epss 0.00

    U-Office Force UserDefault page has insufficient filtering for special characters in the HTTP header fields. A remote attacker with general user privilege can exploit this vulnerability to inject JavaScript and perform XSS (Stored Cross-Site Scripting) attack.