Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-3073


Quanos "SCHEMA ST4" example web templates in version Bootstrap 2019 v2/2021 v1/2022 v1/2022 SP1 v1 or below are prone to JavaScript injection allowing a remote attacker to hijack existing sessions to e.g. other web services in the same environment or execute scripts in the users browser environment. The affected script is '*-schema.js'.


Published

2022-12-14T09:15:09.163

Last Modified

2024-11-21T07:18:46.040

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.1 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System weidmueller 19_iot_md01_lan_h4_s0011_firmware - Yes
Hardware weidmueller 19_iot_md01_lan_h4_s0011 - No
Operating System weidmueller fp_iot_md01_4eu_s2_00000_firmware - Yes
Hardware weidmueller fp_iot_md01_4eu_s2_00000 - No
Operating System weidmueller fp_iot_md01_lan_s2_00000_firmware - Yes
Hardware weidmueller fp_iot_md01_lan_s2_00000 - No
Operating System weidmueller fp_iot_md01_lan_s2_00011_firmware - Yes
Hardware weidmueller fp_iot_md01_lan_s2_00011 - No
Operating System weidmueller fp_iot_md02_4eu_s3_00000_firmware - Yes
Hardware weidmueller fp_iot_md02_4eu_s3_00000 - No
Operating System weidmueller iot-gw30_firmware ≤ 1.16.0 Yes
Hardware weidmueller iot-gw30 - No
Operating System weidmueller iot-gw30-4g-eu_firmware ≤ 1.16.0 Yes
Hardware weidmueller iot-gw30-4g-eu - No
Operating System weidmueller uc20-wl2000-ac_firmware ≤ 1.16.0 Yes
Hardware weidmueller uc20-wl2000-ac - No
Operating System weidmueller uc20-wl2000-iot_firmware ≤ 1.16.0 Yes
Hardware weidmueller uc20-wl2000-iot - No

References