{"id":"CVE-2022-1340","aliases":["GHSA-w83m-rghh-frxj"],"url":"https://o3.security/vulnerability/CVE-2022-1340","summary":"Cross-site Scripting (XSS) - Stored in yetiforcecompany/yetiforcecrm","details":"Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.","published":"2022-08-22T12:10:14Z","modified":"2026-08-12T03:51:25.056391185Z","cvss":{"score":7,"severity":"HIGH","vector":"CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H"},"epss":{"score":0.0049,"percentile":0.41024,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"yetiforce/yetiforce-crm","fixedVersion":"6.4.0"}],"fix":{"url":"https://github.com/yetiforcecompany/yetiforcecrm/commit/2c14baaf8dbc7fd82d5c585f2fa0c23528450618","label":"yetiforcecompany/yetiforcecrm@2c14baa"},"references":[{"type":"WEB","url":"https://huntr.dev/bounties/4746f149-fc55-48a1-a7ab-fd7c7412c05a"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/1xxx/CVE-2022-1340.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-1340"},{"type":"FIX","url":"https://github.com/yetiforcecompany/yetiforcecrm/commit/2c14baaf8dbc7fd82d5c585f2fa0c23528450618"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:25.056391185Z"}}