CVE-2022-50963 | uBidAuction 2.0.1 GET active filter date_created/date_from/date_to/created_at cross site scripting (Exploit 50693 / EUVD-2022-55984)
A vulnerability was found in uBidAuction 2.0.1 and classified as problematic. The impacted element is the function filter of the file auctions/myAuctions/status/active of the component GET Handler. Such manipulation of the argument date_created/date_from/date_to/created_at leads to cross site scripting.
This vulnerability is traded as CVE-2022-50963. The attack may be launched remotely. Furthermore, there is an exploit available.