PT-2022-6243 · Vinteo · Vinteo Vcc

D. Kiryukhin

·

Published

2022-11-01

·

Updated

2025-02-05

·

CVE-2022-48020

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Vinteo VCC version 2.36.4
Description The issue is related to the lack of protection for the web page structure, allowing a remote attacker to conduct a cross-site scripting (XSS) attack. This vulnerability enables attackers to inject arbitrary code, which will be executed by the victim user's browser. The attack is conducted via the conference parameter.
Recommendations For version 2.36.4, consider disabling access to the vulnerable conference parameter until a patch is available. Restricting the use of this parameter can help minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

BDU:2023-00632
CVE-2022-48020

Affected Products

Vinteo Vcc