CVE-2022-29540
Summary
| CVE | CVE-2022-29540 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-06-02 14:15:00 UTC |
| Updated | 2022-06-09 20:11:00 UTC |
| Description | resi-calltrace in RESI Gemini-Net 4.2 is affected by Multiple XSS issues. Unauthenticated remote attackers can inject arbitrary web script or HTML into an HTTP GET parameter that reflects user input without sanitization. This exists on numerous application endpoints, |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Resi | Gemini-net | 4.2 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| GEMINI-NET ™ - NETWORK & SERVICE MONITORING - RESI Informatica | MISC | www.resi.it | |
| www.gruppotim.it/it/footer/red-team.html | MISC | www.gruppotim.it | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.