PT-2022-25265 · Unknown · Videojet Multi 4000

Published

2022-10-27

·

Updated

2022-10-31

·

CVE-2022-40184

CVSS v3.1

5.1

Medium

VectorAV:N/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions VIDEOJET multi 4000 (affected versions not specified)
Description The issue concerns incomplete filtering of JavaScript code in different configuration fields of the web-based interface. An attacker with administrative credentials can store JavaScript code that will be executed for all administrators accessing the same configuration option.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-40184

Affected Products

Videojet Multi 4000