PT-2022-21361 · Pimcore+2 · Pimcore+1
Kingjia90
·
Published
2022-09-21
·
Updated
2022-09-23
·
CVE-2022-3255
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
No specific software name is mentioned, but based on the information provided, the affected software is likely a web application.
Since the affected versions are not explicitly mentioned, the output will be:
Web application (affected versions not specified)
Description
If an attacker can control a script that is executed in the victim's browser, then they can typically fully compromise that user. The attacker can perform any action within the application that the user can perform, view any information that the user is able to view, modify any information that the user is able to modify, and initiate interactions with other application users, including malicious attacks, that will appear to originate from the initial victim user.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pimcore
Pimcore/Pimcore