PT-2022-20714 · Proxmox · Proxmox Virtual Environment
Cursered
+1
·
Published
2022-12-14
·
Updated
2024-10-29
·
CVE-2022-31358
CVSS v3.1
9.0
Critical
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Proxmox Virtual Environment versions prior to 7.2-3
Description
A reflected cross-site scripting (XSS) issue allows remote attackers to execute arbitrary web scripts or HTML via non-existent endpoints under the path "/api2/html/". This enables attackers to potentially manipulate web content.
Recommendations
For versions prior to 7.2-3, update to version 7.2-3 or later to resolve the issue. As a temporary workaround, consider restricting access to non-existent endpoints under the "/api2/html/" path to minimize the risk of exploitation.
Exploit
Fix
RCE
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Proxmox Virtual Environment