Lucene search

K
cvelistMitreCVELIST:CVE-2022-24957
HistoryMar 29, 2022 - 1:11 a.m.

CVE-2022-24957

2022-03-2901:11:38
mitre
www.cve.org
3
cve-2022-24957
dhc vision eqms
persistent xss
untrusted input/output
xss payload
information object
version tab

EPSS

0.001

Percentile

21.4%

DHC Vision eQMS through 5.4.8.322 has Persistent XSS due to insufficient encoding of untrusted input/output. To exploit the vulnerability, the attacker has to create or edit a new information object and use the XSS payload as the name. Any user that opens the object’s version or history tab will be attacked.

EPSS

0.001

Percentile

21.4%

Related for CVELIST:CVE-2022-24957