First published: Mon Aug 15 2022(Updated: )
Authenticated stored cross-site scripting (XSS) vulnerability in "Field Server Address" field in INTELBRAS ATA 200 Firmware 74.19.10.21 allows attackers to inject JavaScript code through a crafted payload.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
INTELBRAS ATA 200 Firmware | =74.19.10.21 | |
INTELBRAS ATA 200 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-24654 is an authenticated stored cross-site scripting (XSS) vulnerability in the "Field Server Address" field in INTELBRAS ATA 200 Firmware 74.19.10.21.
CVE-2022-24654 allows attackers to inject JavaScript code through a crafted payload in the "Field Server Address" field.
The severity of CVE-2022-24654 is medium with a CVSS score of 5.4.
To fix CVE-2022-24654, update to a version of the INTELBRAS ATA 200 Firmware that is not affected by this vulnerability.
More information about CVE-2022-24654 can be found at the following references: [http://intelbras.com](http://intelbras.com), [https://github.com/leonardobg/CVE-2022-24654](https://github.com/leonardobg/CVE-2022-24654), [https://packetstormsecurity.com/files/168064/Intelbras-ATA-200-Cross-Site-Scripting.html](https://packetstormsecurity.com/files/168064/Intelbras-ATA-200-Cross-Site-Scripting.html)