PT-2022-24385 · Unknown · Eyes Of Network Web Application

Published

2022-08-15

·

Updated

2022-08-16

·

CVE-2022-38357

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Eyes of Network Web application (affected versions not specified)
Description The issue is related to the improper neutralization of special elements, making the Eyes of Network Web application susceptible to an iFrame injection attack. This attack can be executed via the url parameter of the "/module/module frame/index.php" API endpoint.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2022-38357

Affected Products

Eyes Of Network Web Application