Junglewise Threat Intelligence

CVE-2022-50964: ApPHP uBidAuction reflected XSS in filter module

CVE-2022-50964 · Severity: medium · CVSS 6.1 · Published 2026-05-10

Technologies: ApPHP uBidAuction. Vendors: ApPHP.

Executive brief

uBidAuction is a web-based platform used to create and manage online auction websites. A security flaw in its filtering system allows attackers to send malicious links to users that, when clicked, execute unauthorized scripts in the user's browser. This could lead to the theft of login sessions, unauthorized access to user accounts, or the display of fraudulent content to customers and administrators.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in uBidAuction v2.0.1 due to improper sanitization of input parameters within the filter web module. Specifically, the 'date_created', 'date_from', 'date_to', and 'created_at' parameters are vulnerable across several components, including myOrders, myAuctions, and various management modules (posts, news, tickets). An unauthenticated remote attacker can exploit this by crafting a malicious GET request containing a script payload. If a victim (member or admin) visits the crafted URL, the script executes in their browser context, potentially allowing for session hijacking (cookie theft), external redirects, or unauthorized actions performed on behalf of the user.

Affected products

  • ApPHP uBidAuction 2.0.1

Timeline

  • 2022-01-21: disclosed: Public disclosure by Vulnerability Laboratory
  • 2026-05-10: advisory: NVD publication date

References

Related threats