CVE-2022-22812: XSS
Published Feb 9, 2022
·Updated
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause a web session compromise when an attacker injects and then executes arbitrary malicious JavaScript code inside the target browser. Affected Product: spaceLYnk (V2.6.2 and prior), Wiser for KNX (formerly homeLYnk) (V2.6.2 and prior), fellerLYnk (V2.6.2 and prior)
Affected Software
6 affected components
Schneider-electric Spacelynk Firmware<=2.6.2
Schneider-electric Spacelynk
Schneider-electric Wiser For Knx Firmware<=2.6.2
Schneider-electric Wiser For Knx
Schneider-electric Fellerlynk Firmware<=2.6.2
Schneider-electric Fellerlynk
Remediation
Event History
Feb 9, 2022
CVE Published
via MITRE·10:05 PM
Data Sourced
via MITRE·10:05 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-22812.
2
What is the severity level of CVE-2022-22812?
The severity level of CVE-2022-22812 is medium.
3
What is the CWE ID of CVE-2022-22812?
The CWE ID of CVE-2022-22812 is CWE-79.
4
Which product is affected by CVE-2022-22812?
The affected product is spaceLYnk (V2.6.2).
5
How can CVE-2022-22812 be exploited?
CVE-2022-22812 can be exploited by injecting and executing arbitrary malicious JavaScript code in the target browser.