PT-2025-54235 · Pulse+3 · Pulse+3

Published

2025-12-30

·

Updated

2025-12-31

·

CVE-2022-50787

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x
Description The software contains an unauthenticated stored cross-site scripting issue. An attacker can inject malicious scripts through the username parameter. This allows execution of arbitrary HTML and JavaScript code in a victim’s browser session without requiring authentication.
Recommendations Apply input validation and sanitization to the username parameter to prevent the injection of malicious scripts.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-50787

Affected Products

Eco
First
Pulse
Sound4 Impact