PT-2024-11558 · Ovaledge · Ovaledge

Published

2024-10-25

·

Updated

2024-10-31

·

CVE-2022-30360

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OvalEdge versions 5.2.8.0 and earlier
Description The issue is related to multiple Stored XSS (also known as Persistent or Type II) vulnerabilities. These vulnerabilities can be exploited via a POST request to the "/profile/updateProfile" API endpoint, specifically through the slackid or phone parameters. It is noted that authentication is required to exploit this issue.
Recommendations For OvalEdge versions 5.2.8.0 and earlier, as a temporary workaround, consider disabling the /profile/updateProfile API endpoint or restricting access to the slackid and phone parameters until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-30360

Affected Products

Ovaledge