PT-2022-20714 · Proxmox · Proxmox Virtual Environment

Cursered

+1

·

Published

2022-12-14

·

Updated

2024-10-29

·

CVE-2022-31358

CVSS v3.1

9.0

Critical

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Proxmox Virtual Environment versions prior to 7.2-3
Description A reflected cross-site scripting (XSS) issue allows remote attackers to execute arbitrary web scripts or HTML via non-existent endpoints under the path "/api2/html/". This enables attackers to potentially manipulate web content.
Recommendations For versions prior to 7.2-3, update to version 7.2-3 or later to resolve the issue. As a temporary workaround, consider restricting access to non-existent endpoints under the "/api2/html/" path to minimize the risk of exploitation.

Exploit

Fix

RCE

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-31358

Affected Products

Proxmox Virtual Environment