CVE-2022-24654: XSS
Authenticated stored cross-site scripting (XSS) vulnerability in "Field Server Address" field in INTELBRAS ATA 200 Firmware 74.19.10.21 allows attackers to inject JavaScript code through a crafted payload.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-24654?
CVE-2022-24654 is an authenticated stored cross-site scripting (XSS) vulnerability in the "Field Server Address" field in INTELBRAS ATA 200 Firmware 74.19.10.21.
How does CVE-2022-24654 affect INTELBRAS ATA 200 Firmware?
CVE-2022-24654 allows attackers to inject JavaScript code through a crafted payload in the "Field Server Address" field.
What is the severity of CVE-2022-24654?
The severity of CVE-2022-24654 is medium with a CVSS score of 5.4.
How can I fix CVE-2022-24654?
To fix CVE-2022-24654, update to a version of the INTELBRAS ATA 200 Firmware that is not affected by this vulnerability.
Where can I find more information about CVE-2022-24654?
More information about CVE-2022-24654 can be found at the following references: [http://intelbras.com](http://intelbras.com), [https://github.com/leonardobg/CVE-2022-24654](https://github.com/leonardobg/CVE-2022-24654), [https://packetstormsecurity.com/files/168064/Intelbras-ATA-200-Cross-Site-Scripting.html](https://packetstormsecurity.com/files/168064/Intelbras-ATA-200-Cross-Site-Scripting.html)