CVE-2022-25781: Reflected XSS issues in GateManager
Cross-site Scripting (XSS) vulnerability in Web UI of Secomea GateManager allows phishing attacker to inject javascript or html into logged in user session.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-25781?
CVE-2022-25781 is a Cross-site Scripting (XSS) vulnerability in the Web UI of Secomea GateManager.
How does CVE-2022-25781 work?
CVE-2022-25781 allows a phishing attacker to inject JavaScript or HTML into a logged-in user session.
Which software versions of Secomea GateManager are affected by CVE-2022-25781?
Secomea GateManager 4250 Firmware versions up to and excluding 9.7.622134021, Secomea GateManager 4260 Firmware versions up to and excluding 9.7.622134021, Secomea GateManager 8250 Firmware versions up to and excluding 9.7.622134021, and Secomea GateManager 9250 Firmware versions up to and excluding 9.7.622134021 are affected.
What is the severity of CVE-2022-25781?
CVE-2022-25781 has a severity value of 6.1 (Medium).
How do I fix CVE-2022-25781?
To fix CVE-2022-25781, update Secomea GateManager to a version beyond 9.7.622134021.