CVE-2022-50962 | uBidAuction 2.0.1 orders/myOrders filter date_from/date_to/created_at cross site scripting (Exploit 50693 / EUVD-2022-55983)
A vulnerability classified as problematic was found in uBidAuction 2.0.1. This vulnerability affects the function filter of the file orders/myOrders. Executing a manipulation of the argument date_from/date_to/created_at can lead to cross site scripting.
This vulnerability is registered as CVE-2022-50962. It is possible to launch the attack remotely. Furthermore, an exploit is available.