Junglewise Threat Intelligence

CVE-2022-50969: ApPHP uBidAuction reflected XSS in filter parameters

CVE-2022-50969 · Severity: medium · CVSS 6.1 · Published 2026-05-10

Technologies: ApPHP uBidAuction, ApPHP MVC Framework. Vendors: ApPHP.

Executive brief

uBidAuction is a web-based platform used to create and manage online auction websites. A security flaw in its filtering system allows attackers to trick users into executing malicious scripts in their own browsers. This could lead to unauthorized access to user sessions, theft of sensitive information, or redirection to fraudulent websites.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in uBidAuction v2.0.1 and ApPHP MVC Framework v1.2.2. The root cause is improper neutralization of input in the 'date_created', 'date_from', 'date_to', and 'created_at' parameters within the filter functionality of various modules, including backend/mailingLog/manage, orders/myOrders, and auctions/manage. A remote, unauthenticated attacker can exploit this by crafting a malicious GET request and tricking a user into clicking a link. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, enabling session hijacking, cookie theft, or unauthorized actions on behalf of the user.

Affected products

  • ApPHP uBidAuction 2.0.1
  • ApPHP ApPHP MVC Framework 1.2.2

Timeline

  • 2022-01-21: disclosed: Public disclosure by Vulnerability Laboratory
  • 2022-02-02: other: Exploit published on Exploit-DB
  • 2026-05-10: advisory: NVD publication date

References

Related threats