CVE-2022-50968 | uBidAuction 2.0.1 GET auctions/manage filter date_created/date_from/date_to/created_at cross site scripting (Exploit 50693 / EUVD-2022-55989)
A vulnerability labeled as problematic has been found in uBidAuction 2.0.1. This affects the function filter of the file auctions/manage of the component GET Handler. Such manipulation of the argument date_created/date_from/date_to/created_at leads to cross site scripting.
This vulnerability is referenced as CVE-2022-50968. It is possible to launch the attack remotely. Furthermore, an exploit is available.