PT-2022-1903 · Hewlett Packard+1 · Hp Print+2
Angelboy
·
Published
2022-01-21
·
Updated
2024-08-27
·
CVE-2022-3942
CVSS v2.0
8.3
High
| Vector | AV:A/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SourceCodester Sanitization Management System (affected versions not specified)
HP Print and HP Digital Sending products (affected versions not specified)
Description
A vulnerability was found in the SourceCodester Sanitization Management System, classified as problematic, affecting some unknown processing of the file
php-sms/?p=request quote, leading to cross-site scripting. The attack may be initiated remotely. Additionally, a vulnerability in the implementation of the TCP/IP Link-Local Multicast Name Resolution (LLMNR) protocol in HP Print and HP Digital Sending products is related to a buffer overflow in the stack, which may allow a remote attacker to execute arbitrary code.Recommendations
For SourceCodester Sanitization Management System, consider disabling the
php-sms/?p=request quote endpoint until a patch is available.
For HP Print and HP Digital Sending products, restrict access to the LLMNR protocol to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Improper Neutralization
XSS
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hp Digital Sending
Hp Print
Sourcecodester Sanitization Management System