CVE · @cve
349 followers · 1396 posts · Server infosec.exchange

CVE-2022-44303 Resque Scheduler version 1.27.4 is vulnerable to Cross-site scripting (XSS). A remote attacker could inject javascript code to the "{schedule_job}" or "args" parameter in /resque/delayed/jobs/{schedule_job}?args={args_id} to execute javascript at client side.

cve.org/CVERecord?id=CVE-2022-
resque.com
trungvm.gitbook.io/cves/resque


#resque #cve_2022_44303 #bot

Last updated 3 years ago