PT-2022-15755 · Unknown · Vulnerable Device

Aarón Flecha Menéndez

·

Published

2022-03-09

·

Updated

2023-06-27

·

CVE-2022-22985

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions No specific software or versions mentioned, use: Vulnerable device (affected versions not specified)
Description The issue allows attackers to inject malicious code into the web application of the vulnerable device due to the absence of filters when loading certain sections. This malicious code is executed when a legitimate user accesses the specific web section where the information is displayed, allowing for the injection of code on specific parameters, such as parameters, when a user attempts to review history.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2022-22985

Affected Products

Vulnerable Device