CVE-2022-40190
Summary
| CVE | CVE-2022-40190 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-10-31 21:15:00 UTC |
| Updated | 2022-11-02 14:13:00 UTC |
| Description | SAUTER Controls moduWeb firmware version 2.7.1 is vulnerable to reflective cross-site scripting (XSS). The web application does not adequately sanitize request strings of malicious JavaScript. An attacker utilizing XSS could then execute malicious code in users’ browsers and steal sensitive information, including user credentials. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Sauter-controls | Moduweb Firmware | 2.7.1 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SAUTER Controls moduWeb | CISA | MISC | www.cisa.gov | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Ithaca Labs of Odyssey Cyber Security reported this vulnerability.
There are currently no legacy QID mappings associated with this CVE.