uBidAuction 2.0.1 contains a reflected cross-site...
Moderate severity
Unreviewed
Published
May 10, 2026
to the GitHub Advisory Database
•
Updated May 10, 2026
Description
Published by the National Vulnerability Database
May 10, 2026
Published to the GitHub Advisory Database
May 10, 2026
Last updated
May 10, 2026
uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the orders/myOrders module. The date_created, date_from, date_to, and created_at parameters in the filter functionality are not properly sanitized, allowing remote attackers to inject malicious scripts via crafted GET requests that execute in victims' browsers.
References