Loading
Generated remediation guidance and an executive summary. No account required.
Stored XSS in "Name", "Group Name" & "Title" in GitHub repository polonel/trudesk prior to v1.2.0. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive data exposure, and worse.
Cite this page
CVE-2022-1290. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2022-1290
Use CWE-79, Trudesk Project vendor hub and Trudesk product page to widen CVE-2022-1290 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2022-2128, CVE-2022-2023 and CVE-2022-1808 for nearby disclosures in the same product family.