Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-0043 | A vulnerability classified as problematic was found in collective.contact.widget up to 1.12. This vulnerability affects the function title of the file src/collective/contact/widget/widgets.py. The manipulation leads to cross site scripting. The attack can be initiated remotely. The name of the patch is 5da36305ca7ed433782be8901c47387406fcda12. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-216496. |
Github GHSA |
GHSA-5pqf-rvm7-3wgw | collective.contact.widget is vulnerable to cross-site scripting |
Mon, 14 Apr 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-04-14T17:27:52.132Z
Reserved: 2022-12-21T00:00:00.000Z
Link: CVE-2022-4638
Updated: 2024-08-03T01:48:39.567Z
Status : Modified
Published: 2022-12-21T22:15:08.570
Modified: 2024-11-21T07:35:38.760
Link: CVE-2022-4638
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA