
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2022-1988 is a Cross-site Scripting (XSS) vulnerability discovered in GitHub repository neorazorx/facturascripts prior to version 2022.09. The vulnerability was disclosed on June 3, 2022 (CVE Mitre).
The vulnerability is a generic Cross-site Scripting (XSS) issue that affects the description field handling in the application. The fix involved implementing HTML sanitization for the description field, as evidenced by the code changes that added HTML escaping functionality (GitHub Commit).
The Cross-site Scripting vulnerability could allow attackers to inject malicious scripts into the application, potentially leading to unauthorized access to user data, session hijacking, or other client-side attacks (Huntr Report).
The vulnerability was patched in version 2022.09 of facturascripts. Users should upgrade to this version or later to receive the security fix. The patch implements proper HTML sanitization for the description field (GitHub Commit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."