S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-31299 Scanner

CVE-2022-31299 scanner - Cross-Site Scripting (XSS) vulnerability in Haraj

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.7k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-31299
6.1
CVSS

Haraj v3.7 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the User Upgrade Form.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

Haraj is a popular software application that facilitates online marketplaces in the Middle Eastern region. Launched in 2011, the platform serves as a hub for buyers and sellers to engage in commerce in a safe and efficient manner. The application is available on both iOS and Android platforms and also has a website that customers can access from their web browsers. By using Haraj, users can buy and sell anything ranging from cars, mobile phones, furniture to even real estate properties.

The CVE-2022-31299 vulnerability was recently detected in the Haraj v3.7 software application. This vulnerability is a reflected cross-site scripting (XSS) vulnerability that exists in the User Upgrade Form. A reflected XSS attack is a type of cyberattack where an attacker injects malicious code into a web page, which is then sent to a victim's browser through an otherwise legitimate website. The vulnerability code allows hackers to execute malicious code by tricking the victim into clicking a link that contains the code.

Exploiting this vulnerability can lead to attackers gaining unwarranted access to a user's personal data, including sensitive information such as bank details and login credentials. Once the attacker gains access, they can steal, destroy or even manipulate this information for their own purposes, such as identity theft or financial fraud. This can cause severe harm to the victim and potentially lead to disastrous consequences.

Thanks to the pro features of s4e.io platform, users can stay up-to-date with the latest developments in cybersecurity. By accessing this platform, they can easily and quickly learn about any vulnerabilities present in their digital assets. This will help them protect against any unforeseen cyberattacks and ensure their online safety and security.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users can take the following precautions:

  • Ensure that Haraj v3.7 is patched to the latest version.
  • Be careful when clicking on links or opening emails from unknown sources.
  • Use two-factor authentication to add an extra layer of security to their account.
  • Secure their browsing experience by using a reputable antivirus program.
  • Enable firewalls on their devices.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.