PT-2022-16547 · Boltwire · Boltwire

David Silva

·

Published

2022-02-15

·

Updated

2023-12-21

·

CVE-2022-24227

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions BoltWire versions 7.10 through 8.00
Description A cross-site scripting (XSS) issue allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the name and lastname parameters.
Recommendations For BoltWire version 7.10, update to a version later than 8.00 to resolve the issue. For BoltWire version 8.00, update to a version later than 8.00 to resolve the issue. As a temporary workaround, consider restricting the use of the name and lastname parameters until a patch is available.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-24227

Affected Products

Boltwire