GHSA-f24c-hgx2-f289MediumCVSS 5.4

In vFairs 3.3, any user logged in to a vFairs virtual conference or event can modify any other...

Published
May 24, 2022
Last Modified
July 5, 2026

🔗 CVE IDs covered (1)

📋 Description

In vFairs 3.3, any user logged in to a vFairs virtual conference or event can modify any other users profile information to include a cross-site scripting payload. The user data stored by the database includes HTML tags that are intentionally rendered out onto the page, and this can be abused to perform XSS attacks.

🔗 References (4)