CVE-2022-40912
Summary
| CVE | CVE-2022-40912 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-09-28 14:15:00 UTC |
| Updated | 2022-09-30 18:20:00 UTC |
| Description | ETAP Lighting International NV ETAP Safety Manager 1.0.0.32 is vulnerable to Cross Site Scripting (XSS). Input passed to the GET parameter 'action' is not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML/JS code in a user's browser session in context of an affected site. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Etaplighting | Etap Safety Manager | 1.0.0.32 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Zero Science Lab » ETAP Safety Manager 1.0.0.32 Remote Unauthenticated Reflected XSS | MISC | www.zeroscience.mk | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.