First published: Wed May 04 2022(Updated: )
Cross-site Scripting (XSS) vulnerability in Web GUI of SiteManager allows logged-in user to inject scripting. This issue affects: Secomea SiteManager all versions prior to 9.7.
Credit: VulnerabilityReporting@secomea.com
Affected Software | Affected Version | How to fix |
---|---|---|
Secomea Sitemanager | <9.7.622134021 | |
Secomea Sitemanager | ||
Secomea Sitemanager | <9.7.622134021 | |
Secomea Sitemanager | ||
Secomea Sitemanager Firmware | <9.7.622134021 | |
Secomea Sitemanager 1149 Firmware | ||
Secomea Sitemanager 3329 Firmware | <9.7.622134021 | |
Secomea Sitemanager 3329 Firmware | ||
Secomea Sitemanager 3339 Firmware | <9.7.622134021 | |
Secomea Sitemanager | ||
Secomea Sitemanager 3349 Firmware | <9.7.622134021 | |
Secomea Sitemanager | ||
Secomea Sitemanager 3529 Firmware | <9.7.622134021 | |
Secomea Sitemanager 3529 Firmware | ||
Secomea Sitemanager | <9.7.622134021 | |
Secomea Sitemanager | ||
Secomea SiteManager | <9.7.622134021 | |
Secomea Sitemanager |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-25784 is a Cross-site Scripting (XSS) vulnerability in the Web GUI of SiteManager.
All versions of Secomea SiteManager prior to 9.7.622134021 are affected by CVE-2022-25784.
CVE-2022-25784 has a severity rating of 4.8 (critical).
The CWE ID for CVE-2022-25784 is 79.
To fix CVE-2022-25784, it is recommended to update Secomea SiteManager to version 9.7.622134021 or later.