The user input was not sanitized on Reporting Hierarchy Management page of Foreseer Reporting Software (FRS) application which could lead into execution of arbitrary JavaScript in a browser context
for all the interacting users. This security issue has been patched in the latest version 1.5.100 of the FRS.
Metrics
Affected Vendors & Products
References
History
Tue, 26 Aug 2025 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-20 |
Tue, 26 Aug 2025 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 |
Tue, 04 Mar 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 28 Feb 2025 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The user input was not sanitized on Reporting Hierarchy Management page of Foreseer Reporting Software (FRS) application which could lead into execution of arbitrary JavaScript in a browser context for all the interacting users. This security issue has been patched in the latest version 1.5.100 of the FRS. | |
| Title | Improper Input Validation in Foreseer Reporting Software (FRS) | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Eaton
Published: 2025-02-28T08:24:21.219Z
Updated: 2025-08-26T10:19:15.302Z
Reserved: 2025-01-07T09:41:16.733Z
Link: CVE-2025-22491
Updated: 2025-02-28T13:21:18.644Z
Status : Awaiting Analysis
Published: 2025-02-28T09:15:12.540
Modified: 2025-08-26T11:15:32.053
Link: CVE-2025-22491
No data.