PT-2022-15974 · Cedar Gate · Cedar Gate Ez-Net Portal

Published

2022-03-04

·

Updated

2025-07-14

·

CVE-2022-23397

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Cedar Gate EZ-NET portal versions 6.5.5 through 6.8.0
Description The issue arises from a call to display messages to users that does not properly sanitize data sent through a URL parameter, leading to a Reflected Cross-Site Scripting vulnerability. The vendor disputes this vulnerability due to a lack of clear steps for reproduction.
Recommendations For versions 6.5.5 through 6.8.0, consider disabling the functionality that displays messages to users until a proper fix is implemented to sanitize the URL parameter. Restrict access to the vulnerable URL parameter to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-23397

Affected Products

Cedar Gate Ez-Net Portal