Vulnerability Description
DHC Vision eQMS through 5.4.8.322 has Persistent XSS due to insufficient encoding of untrusted input/output. To exploit the vulnerability, the attacker has to create or edit a new information object and use the XSS payload as the name. Any user that opens the object's version or history tab will be attacked.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dhc-Vision | Eqms | <= 5.4.8.322 |
Related Weaknesses (CWE)
References
- https://syss.deThird Party Advisory
- https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2022-019.tExploitMitigationThird Party Advisory
- https://syss.deThird Party Advisory
- https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2022-019.tExploitMitigationThird Party Advisory
FAQ
What is CVE-2022-24957?
CVE-2022-24957 is a vulnerability with a CVSS score of 5.4 (MEDIUM). DHC Vision eQMS through 5.4.8.322 has Persistent XSS due to insufficient encoding of untrusted input/output. To exploit the vulnerability, the attacker has to create or edit a new information object a...
How severe is CVE-2022-24957?
CVE-2022-24957 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-24957?
Check the references section above for vendor advisories and patch information. Affected products include: Dhc-Vision Eqms.