First published: Wed Mar 30 2022(Updated: )
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Group Functionality of Profelis IT Consultancy SambaBox allows AUTHENTICATED user to cause execute arbitrary codes on the vulnerable server. This issue affects: Profelis IT Consultancy SambaBox 4.0 version 4.0 and prior versions on x86.
Credit: cve@profelis.com.tr
Affected Software | Affected Version | How to fix |
---|---|---|
Profelis Informatics SambaBox | <=4.0 |
Upgrade SambaBox to 4.1
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-25620 is classified as a high severity vulnerability due to the potential for an authenticated user to execute arbitrary code on the server.
To mitigate CVE-2022-25620, upgrade Profelis IT Consultancy SambaBox to version 4.1 or higher where the vulnerability has been addressed.
CVE-2022-25620 is classified as a cross-site scripting (XSS) vulnerability, specifically due to improper neutralization of script-related HTML tags.
CVE-2022-25620 affects all authenticated users of Profelis IT Consultancy SambaBox versions up to and including 4.0.
Exploitation of CVE-2022-25620 could lead to unauthorized execution of arbitrary code on the server, potentially compromising system integrity.