Junglewise Threat Intelligence

CVE-2022-50962: ApPHP uBidAuction reflected XSS in multiple filter parameters

CVE-2022-50962 · Severity: medium · CVSS 6.1 · Published 2026-05-10

Technologies: ApPHP uBidAuction. Vendors: ApPHP.

Executive brief

uBidAuction, a software platform used to create and manage online auction websites, contains a security flaw in its order and auction management modules. An attacker can trick a user into clicking a malicious link, allowing the attacker to run unauthorized scripts in the user's web browser. This could lead to the theft of login sessions, unauthorized access to account information, or the display of fraudulent content to users.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in uBidAuction v2.0.1 due to improper neutralization of input in the 'filter' web module. Specifically, the parameters 'date_created', 'date_from', 'date_to', and 'created_at' are not properly sanitized before being rendered in the application's response. An unauthenticated remote attacker can exploit this by crafting a malicious GET request containing a script payload and tricking a user (member or admin) into visiting the URL. Successful exploitation allows for the execution of arbitrary JavaScript in the victim's browser session, potentially leading to session hijacking or unauthorized actions on behalf of the user.

Affected products

  • ApPHP uBidAuction 2.0.1

Timeline

  • 2022-01-21: disclosed: Public disclosure by Vulnerability Laboratory
  • 2022-09-02: other: Vendor notification
  • 2026-05-10: advisory: NVD publication date

References

Related threats