CVE-2022-50965
uBidAuction 2.0.1 posts manage Reflected XSS
CVSS Score
6.1
EPSS Score
0.0%
EPSS Percentile
11th
uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the posts/manage module. The date_created, date_from, date_to, and created_at parameters in the filter functionality are not properly sanitized, allowing remote attackers to inject malicious scripts via crafted GET requests that execute in victims' browsers.
| CWE | CWE-79 |
| Vendor | ubidauction |
| Product | ubidauction |
| Published | May 10, 2026 |
| Last Updated | May 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for ubidauction ubidauction
Be the first to know when new medium vulnerabilities affecting ubidauction ubidauction are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
None
Integrity
None
Availability
None
Affected Versions
uBidAuction / uBidAuction
2.0.1
References
exploit-db.com: https://www.exploit-db.com/exploits/50693 vulnerability-lab.com: https://www.vulnerability-lab.com/get_content.php?id=2289 apphp.com: https://www.apphp.com/codemarket/items/48/ubidauction-php-classic-and-bid-auctions-script vulncheck.com: https://www.vulncheck.com/advisories/ubidauction-posts-manage-reflected-xss
Credits
Vulnerability-Lab [Research Team]