PT-2022-25617 · Etap · Etap Safety Manager

Gjoko Krstic

·

Published

2022-09-28

·

Updated

2022-09-30

·

CVE-2022-40912

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions ETAP Safety Manager version 1.0.0.32
Description The issue concerns a Cross Site Scripting (XSS) problem. Input passed to the GET parameter action is not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML/JS code in a user's browser session in context of an affected site.
Recommendations For ETAP Safety Manager version 1.0.0.32, consider restricting access to the action parameter in the GET request to minimize the risk of exploitation. As a temporary workaround, avoid using the action parameter until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-40912

Affected Products

Etap Safety Manager