{"id":"PYSEC-2022-43182","details":"Withdrawn as duplicate of PYSEC-2022-239. The time and filter parameters in Fava prior to v1.22 are vulnerable to reflected XSS due to the lack of escaping of error messages which contained the parameters in verbatim.","aliases":["CVE-2022-2514","GHSA-xrf4-39fm-j5f2","PYSEC-2022-239"],"modified":"2026-07-09T16:45:04.841180980Z","published":"2022-07-25T14:15:10.873Z","withdrawn":"2026-07-09T14:54:00Z","references":[{"type":"FIX","url":"https://github.com/beancount/fava/commit/ca9e3882c7b5fbf5273ba52340b9fea6a99f3711"},{"type":"FIX","url":"https://huntr.dev/bounties/dbf77139-4384-4dc5-9994-45a5e0747429"}],"affected":[{"package":{"name":"fava","ecosystem":"PyPI","purl":"pkg:pypi/fava"},"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/fava/PYSEC-2022-43182.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}