Vulnerability Description
AlgoSec – FireFlow Reflected Cross-Site-Scripting (RXSS) A malicious user injects JavaScript code into a parameter called IntersectudRule on the search/result.html page. The malicious user changes the request from POST to GET and sends the URL to another user (victim). JavaScript code is executed on the browser of the other user.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Algosec | Fireflow | >= a32.0, < a32.0.580-277 |
Related Weaknesses (CWE)
References
- https://www.gov.il/en/Departments/faq/cve_advisoriesThird Party Advisory
- https://www.gov.il/en/Departments/faq/cve_advisoriesThird Party Advisory
FAQ
What is CVE-2022-36783?
CVE-2022-36783 is a vulnerability with a CVSS score of 6.5 (MEDIUM). AlgoSec – FireFlow Reflected Cross-Site-Scripting (RXSS) A malicious user injects JavaScript code into a parameter called IntersectudRule on the search/result.html page. The malicious user changes the...
How severe is CVE-2022-36783?
CVE-2022-36783 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-36783?
Check the references section above for vendor advisories and patch information. Affected products include: Algosec Fireflow.