Home
HIGH: 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HDefault status
unaffected
5.18
affected
5.03
affected
4.02 (custom)
affected
3.30
affected
Default status
unaffected
Any version before 1.22
affected
Description
A cross-site scripting vulnerability exists in the AccuWeather and Custom RSS widget that allows an unauthenticated user to replace the RSS feed URL with a malicious one.
Problem types
Product status
5.18
5.03
4.02 (custom)
3.30
Any version before 1.22
Credits
Joshua Dillon reported this vulnerability to CISA.
References
www.cisa.gov/news-events/ics-advisories/icsa-25-175-06