CVE-2022-24432
Summary
| CVE | CVE-2022-24432 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-03-10 17:46:00 UTC |
| Updated | 2022-03-16 18:33:00 UTC |
| Description | Persistent cross-site scripting (XSS) in the web interface of ipDIO allows an authenticated remote attacker to introduce arbitrary JavaScript by injecting an XSS payload into specific fields. The XSS payload will be executed when a legitimate user attempts to upload, copy, download, or delete an existing configuration (Administrative Services). |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Ipcomm | Ipdio | - | All | All | All |
| Operating System | Ipcomm | Ipdio Firmware | 3.9 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IPCOMM ipDIO | CISA | MISC | www.cisa.gov | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Aarón Flecha Menéndez of S21Sec reported these vulnerabilities to CISA.
There are currently no legacy QID mappings associated with this CVE.