CVE-2022-3073: Quaonos Schema ST4 example templates prone to XSS
Quanos "SCHEMA ST4" example web templates in version Bootstrap 2019 v2/2021 v1/2022 v1/2022 SP1 v1 or below are prone to JavaScript injection allowing a remote attacker to hijack existing sessions to e.g. other web services in the same environment or execute scripts in the users browser environment. The affected script is '-schema.js'.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-3073.
What is the severity of CVE-2022-3073?
The severity of CVE-2022-3073 is medium.
What is the affected software of CVE-2022-3073?
The affected software of CVE-2022-3073 includes Quanos SCHEMA ST4 example web templates in version Bootstrap 2019 v2/2021 v1/2022 v1/2022 SP1 v1 or below.
What is the impact of CVE-2022-3073?
CVE-2022-3073 allows a remote attacker to hijack existing sessions or execute scripts in the user's browser environment.
How can I fix CVE-2022-3073?
To fix CVE-2022-3073, it is recommended to update the Quanos SCHEMA ST4 example web templates to a version above Bootstrap 2019 v2/2021 v1/2022 v1/2022 SP1 v1.