FlightAirMap version <=v1.0-beta.21 contains a Cross Site Scripting (XSS) vulnerability in GET variable used within registration sub menu page that can result in unauthorised actions and access to data, stealing session information. This vulnerability appears to have been fixed in after commit 22b09a3.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-10-03T16:21:59

Updated: 2022-10-03T16:21:59

Reserved: 2018-08-08T00:00:00


Link: CVE-2018-1000642

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2018-08-20T19:31:37.777

Modified: 2018-10-19T17:26:53.383


Link: CVE-2018-1000642

JSON object: View

cve-icon Redhat Information

No data.

CWE