CVE-2022-50896: Testa
Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.
Testa 3.5.1 contains a reflected cross-site scripting vulnerability in the login.php redirect parameter that allows attackers to inject malicious scripts. Attackers can craft a specially encoded payload in the redirect parameter to execute arbitrary JavaScript in victim's browser context.
Affected products
- Testa Testa: version 3.5.1 only
Published 2026-01-13. Last modified 2026-06-17.