Vulnerability Description
Reflected Cross Site Scripting (XSS) vulnerabilities in AST Agent Time Sheet interface (/vicidial/AST_agent_time_sheet.php) of VICIdial via agent, and search_archived_data parameters. This issue affects: VICIdial 2.14b0.5 versions prior to 3555.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vicidial | Vicidial | 2.14b0.5 |
Related Weaknesses (CWE)
References
- https://www.vicidial.org/VICIDIALforum/viewtopic.php?f=4&t=41300&sid=aacb27a29feVendor Advisory
- https://www.vicidial.org/VICIDIALforum/viewtopic.php?f=4&t=41300&sid=aacb27a29feVendor Advisory
FAQ
What is CVE-2022-34879?
CVE-2022-34879 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Reflected Cross Site Scripting (XSS) vulnerabilities in AST Agent Time Sheet interface (/vicidial/AST_agent_time_sheet.php) of VICIdial via agent, and search_archived_data parameters. This issue affec...
How severe is CVE-2022-34879?
CVE-2022-34879 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-34879?
Check the references section above for vendor advisories and patch information. Affected products include: Vicidial Vicidial.