PT-2022-23450 · Unknown · Rageframe2

·

CVE-2022-36530

·

Published

2022-08-16

·

Updated

2024-02-14

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions rageframe2 version 2.6.37
Description An issue was discovered in the user agent related parameters of the info.php page, specifically a XSS vulnerability.
Recommendations For rageframe2 version 2.6.37, consider restricting access to the info.php page until a patch is available. As a temporary workaround, avoid using user agent related parameters in the info.php page to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-36530

Affected Products

Rageframe2