Description A limited SQL injection risk was identified in the "browse list of users" site administration page. Remediation References CVE-2022-40315 Related Vulnerabilities YetiForce CRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-2829) WordPress Plugin WP Statistics Cross-Site Scripting (12.0.8.1) Apache HTTP Server Other Vulnerability (CVE-2002-0654) WordPress Plugin Duplicator-WordPress Migration Remote Code Execution (1.2.40) WordPress Plugin Post Grid, List for WordPress-Content Views Cross-Site Scripting (1.9.0) Severity Critical Classification CVE-2022-40315 CWE-138 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Tags Missing Update Known Vulnerabilities