PT-2022-1903 · Hewlett Packard+1 · Hp Print+2

Angelboy

·

Published

2022-01-21

·

Updated

2024-08-27

·

CVE-2022-3942

CVSS v2.0

8.3

High

VectorAV:A/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SourceCodester Sanitization Management System (affected versions not specified) HP Print and HP Digital Sending products (affected versions not specified)
Description A vulnerability was found in the SourceCodester Sanitization Management System, classified as problematic, affecting some unknown processing of the file php-sms/?p=request quote, leading to cross-site scripting. The attack may be initiated remotely. Additionally, a vulnerability in the implementation of the TCP/IP Link-Local Multicast Name Resolution (LLMNR) protocol in HP Print and HP Digital Sending products is related to a buffer overflow in the stack, which may allow a remote attacker to execute arbitrary code.
Recommendations For SourceCodester Sanitization Management System, consider disabling the php-sms/?p=request quote endpoint until a patch is available. For HP Print and HP Digital Sending products, restrict access to the LLMNR protocol to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Neutralization

XSS

Stack Overflow

Weakness Enumeration

Related Identifiers

BDU:2022-01439
CVE-2022-3942
ZDI-22-532

Affected Products

Hp Digital Sending
Hp Print
Sourcecodester Sanitization Management System