PT-2026-5569 · Unknown · Inciga Web
Published
2022-01-01
·
Updated
2026-02-01
·
CVE-2022-50942
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Inciga Web version 2.8.2
Description
The software contains a client-side cross-site scripting issue that allows remote attackers to inject malicious script codes through the
icinga.min.js file. Attackers can exploit the EventListener.handleEvent() method to execute arbitrary scripts, potentially leading to session hijacking and non-persistent phishing attacks.Recommendations
Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the
icinga.min.js file.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Inciga Web