Description Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. Remediation References CVE-2022-3000 Related Vulnerabilities WordPress Plugin PG Flash Gallery Cross-Site Scripting (4.1.1) Oracle Database Server CVE-2019-2518 Vulnerability (CVE-2019-2518) Apache HTTP Server Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2007-6420) Drupal Core 4.6.x Cross-Site Scripting (4.6.0 - 4.6.5) Ruby Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2013-4164) Severity Medium Classification CVE-2022-3000 CWE-707 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N Tags Missing Update Known Vulnerabilities