Lucene search

K
cveHackeroneCVE-2022-32225
HistoryJul 14, 2022 - 3:15 p.m.

CVE-2022-32225

2022-07-1415:15:08
CWE-79
hackerone
web.nvd.nist.gov
69
4
cve-2022-32225
dom-based xss
veeam management pack
microsoft system center
security vulnerability
nvd

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

31.7%

A reflected DOM-Based XSS vulnerability has been discovered in the Help directory of Veeam Management Pack for Microsoft System Center 8.0. This vulnerability could be exploited by an attacker by convincing a legitimate user to visit a crafted URL on a Veeam Management Pack for Microsoft System Center server, allowing for the execution of arbitrary scripts.

Affected configurations

Nvd
Node
veeammanagement_packMatch8.0microsoft_system_center
VendorProductVersionCPE
veeammanagement_pack8.0cpe:2.3:a:veeam:management_pack:8.0:*:*:*:*:microsoft_system_center:*:*

CNA Affected

[
  {
    "product": "Veeam Management Pack for Microsoft System Center",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "8"
      }
    ]
  }
]

Social References

More

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

31.7%

Related for CVE-2022-32225