CVE-2022-28074: XSS
Published Apr 22, 2022
·Updated
Halo-1.5.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via \admin\index.html#/system/tools.
Affected Software
1 affected component
FIT2CLOUD Halo=1.5.0
Event History
Apr 22, 2022
CVE Published
via MITRE·01:33 PM
Data Sourced
via MITRE·01:33 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-28074.
2
What is the severity level of CVE-2022-28074?
CVE-2022-28074 has a severity level of medium.
3
What is the affected software for CVE-2022-28074?
The affected software for CVE-2022-28074 is Fit2cloud Halo version 1.5.0.
4
What is the type of vulnerability in CVE-2022-28074?
CVE-2022-28074 is a stored cross-site scripting (XSS) vulnerability.
5
How can I fix the vulnerability in Fit2cloud Halo 1.5.0?
To fix the vulnerability in Fit2cloud Halo 1.5.0, it is recommended to update the software to the latest version provided by the vendor.