PT-2022-20156 · Reprise · Reprise Software Rlm License Administration
Mohammed A. Siledar
·
Published
2022-12-29
·
Updated
2025-04-30
·
CVE-2022-30519
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Reprise Software RLM License Administration version 14.2BL4
Description
The issue allows a remote attacker to inject arbitrary code via the
password field in the signing form, potentially leading to code execution.Recommendations
For Reprise Software RLM License Administration version 14.2BL4, consider restricting access to the signing form until a patch is available. As a temporary workaround, avoid using the
password field in the signing form to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Reprise Software Rlm License Administration