GHSA-qv5f-p8rc-6j2qLowCVSS 5.4

Spiceworks Version <= 7.5.00107 is affected by XSS. Any name typed on Custom Groups function is...

Published
May 24, 2022
Last Modified
July 5, 2026

🔗 CVE IDs covered (1)

📋 Description

Spiceworks Version <= 7.5.00107 is affected by XSS. Any name typed on Custom Groups function is vulnerable to stored XSS as they displayed on http://127.0.0.1/inventory/groups/ without output sanitization.

🔗 References (5)