CVE Vulnerabilities

CVE-2022-36325

Published: Aug 10, 2022 | Modified: Jun 27, 2023
CVSS 3.x
4.8
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Affected devices do not properly sanitize data introduced by an user when rendering the web interface. This could allow an authenticated remote attacker with administrative privileges to inject code and lead to a DOM-based XSS.

Affected Software

Name Vendor Start Version End Version
Scalance_m-800_firmware Siemens * *

References