CVE-2022-22571: XSS
Published Apr 11, 2022
·Updated
An authenticated high privileged user can perform a stored XSS attack due to incorrect output encoding in Incapptic connect and affects all current versions.
Affected Software
1 affected component
Ivanti Incapptic Connect<=1.40.3
Event History
Apr 11, 2022
CVE Published
via MITRE·07:38 PM
Data Sourced
via MITRE·07:38 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-22571.
2
What is the severity of CVE-2022-22571?
The severity of CVE-2022-22571 is medium with a severity value of 4.8.
3
What is the description of CVE-2022-22571?
CVE-2022-22571 allows an authenticated high privileged user to perform a stored XSS attack due to incorrect output encoding in Incapptic connect and affects all current versions.
4
What software is affected by CVE-2022-22571?
CVE-2022-22571 affects Ivanti Incapptic Connect up to version 1.40.3.
5
How can I fix CVE-2022-22571?
To fix CVE-2022-22571, it is recommended to update to the latest version of Ivanti Incapptic Connect.