First published: Wed Feb 09 2022(Updated: )
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause a web session compromise when an attacker injects and then executes arbitrary malicious JavaScript code inside the target browser. Affected Product: spaceLYnk (V2.6.2 and prior), Wiser for KNX (formerly homeLYnk) (V2.6.2 and prior), fellerLYnk (V2.6.2 and prior)
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Spacelynk Firmware | <=2.6.2 | |
Schneider-electric Spacelynk Firmware | ||
Wiser for KNX | <=2.6.2 | |
Schneider Electric Wiser for KNX | ||
Schneider Electric Fellerlynk | <=2.6.2 | |
Schneider-electric Fellerlynk Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-22812.
The severity level of CVE-2022-22812 is medium.
The CWE ID of CVE-2022-22812 is CWE-79.
The affected product is spaceLYnk (V2.6.2).
CVE-2022-22812 can be exploited by injecting and executing arbitrary malicious JavaScript code in the target browser.