VYPR

Eharmony

by Synel

CVEs (3)

  • CVE-2022-22791MedJan 28, 2022
    risk 0.43cvss 6.6epss 0.00

    SYNEL - eharmony Authenticated Blind & Stored XSS. Inject JS code into the "comments" field could lead to potential stealing of cookies, loading of HTML tags and JS code onto the system.

  • CVE-2022-36778MedSep 13, 2022
    risk 0.42cvss 6.5epss 0.00

    insert HTML / js code inside input how to get to the vulnerable input : Workers > worker nickname > inject in this input the code.

  • CVE-2022-22790MedJan 28, 2022
    risk 0.36cvss 5.6epss 0.01

    SYNEL - eharmony Directory Traversal. Directory Traversal - is an attack against a server or a Web application aimed at unauthorized access to the file system. on the "Name" parameter the attacker can return to the root directory and open the host file. The path exposes…