PT-2022-16693 · Ipdio · Ipdio
Aarón Flecha Menéndez
·
Published
2022-03-09
·
Updated
2022-03-16
·
CVE-2022-24432
CVSS v3.1
5.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
ipDIO (affected versions not specified)
Description
The issue allows an authenticated remote attacker to introduce arbitrary JavaScript by injecting an XSS payload into specific fields in the web interface. This payload will be executed when a legitimate user attempts to upload, copy, download, or delete an existing configuration, specifically within Administrative Services.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ipdio