CVE-2022-31358: XSS
A reflected cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment prior to v7.2-3 allows remote attackers to execute arbitrary web scripts or HTML via non-existent endpoints under path /api2/html/.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-31358?
CVE-2022-31358 has a severity level of critical.
How does CVE-2022-31358 impact Proxmox Virtual Environment?
CVE-2022-31358 allows remote attackers to execute arbitrary web scripts or HTML via non-existent endpoints under path /api2/html/ in Proxmox Virtual Environment versions prior to v7.2-3.
What is the Common Weakness Enumeration (CWE) ID for CVE-2022-31358?
The CWE ID for CVE-2022-31358 is CWE-79.
Are there any references for CVE-2022-31358?
Yes, you can find references for CVE-2022-31358 at the following links: [http://proxmox.com](http://proxmox.com), [https://git.proxmox.com/?p=pve-http-server.git;a=commitdiff;h=00661f1223b7c0afffa64e1d91f5e018b985f762](https://git.proxmox.com/?p=pve-http-server.git;a=commitdiff;h=00661f1223b7c0afffa64e1d91f5e018b985f762), [https://starlabs.sg/blog/2022/12-multiple-vulnerabilites-in-proxmox-ve--proxmox-mail-gateway/](https://starlabs.sg/blog/2022/12-multiple-vulnerabilites-in-proxmox-ve--proxmox-mail-gateway/)
How can I fix CVE-2022-31358 in Proxmox Virtual Environment?
To fix CVE-2022-31358 in Proxmox Virtual Environment, update to version v7.2-3 or later.