CVE-2022-25620: Stored Cross-Site Scripting (XSS)
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Group Functionality of Profelis IT Consultancy SambaBox allows AUTHENTICATED user to cause execute arbitrary codes on the vulnerable server. This issue affects: Profelis IT Consultancy SambaBox 4.0 version 4.0 and prior versions on x86.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-25620?
CVE-2022-25620 is classified as a high severity vulnerability due to the potential for an authenticated user to execute arbitrary code on the server.
How do I fix CVE-2022-25620?
To mitigate CVE-2022-25620, upgrade Profelis IT Consultancy SambaBox to version 4.1 or higher where the vulnerability has been addressed.
What type of vulnerability is CVE-2022-25620?
CVE-2022-25620 is classified as a cross-site scripting (XSS) vulnerability, specifically due to improper neutralization of script-related HTML tags.
Who is affected by CVE-2022-25620?
CVE-2022-25620 affects all authenticated users of Profelis IT Consultancy SambaBox versions up to and including 4.0.
What consequences can arise from CVE-2022-25620?
Exploitation of CVE-2022-25620 could lead to unauthorized execution of arbitrary code on the server, potentially compromising system integrity.