CVE-2022-26494: XSS
Published Mar 21, 2022
·Updated
An XSS was identified in the Admin Web interface of PrimeKey SignServer before 5.8.1. JavaScript code must be used in a worker name before a Generate CSR request. Only an administrator can update a worker name.
Affected Software
1 affected component
PrimeKey SignServer<5.8.1
Event History
Mar 21, 2022
CVE Published
via MITRE·02:24 PM
Data Sourced
via MITRE·02:24 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-26494?
CVE-2022-26494 is classified as a moderate severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2022-26494?
To fix CVE-2022-26494, update PrimeKey SignServer to version 5.8.1 or later.
3
Who is affected by CVE-2022-26494?
CVE-2022-26494 affects the Admin Web interface of PrimeKey SignServer versions prior to 5.8.1.
4
What can an attacker do with CVE-2022-26494?
An attacker can exploit CVE-2022-26494 to execute malicious JavaScript code by manipulating the worker name in the Generate CSR request.
5
Is administrator access required to exploit CVE-2022-26494?
Yes, only an administrator can update a worker name, which is required for the exploitation of CVE-2022-26494.