Haraj 3.7 contains a cross-site scripting vulnerability in the User Upgrade Form. An attacker can inject malicious script and thus steal authentication credentials and launch other attacks.
id: CVE-2022-31299
info:
name: Haraj 3.7 - Cross-Site Scripting
author: edoardottt
severity:
...