First published: Wed Dec 14 2022(Updated: )
A reflected cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment prior to v7.2-3 allows remote attackers to execute arbitrary web scripts or HTML via non-existent endpoints under path /api2/html/.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Proxmox VE | <7.2-3 | |
<7.2-3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-31358 has a severity level of critical.
CVE-2022-31358 allows remote attackers to execute arbitrary web scripts or HTML via non-existent endpoints under path /api2/html/ in Proxmox Virtual Environment versions prior to v7.2-3.
The CWE ID for CVE-2022-31358 is CWE-79.
Yes, you can find references for CVE-2022-31358 at the following links: [http://proxmox.com](http://proxmox.com), [https://git.proxmox.com/?p=pve-http-server.git;a=commitdiff;h=00661f1223b7c0afffa64e1d91f5e018b985f762](https://git.proxmox.com/?p=pve-http-server.git;a=commitdiff;h=00661f1223b7c0afffa64e1d91f5e018b985f762), [https://starlabs.sg/blog/2022/12-multiple-vulnerabilites-in-proxmox-ve--proxmox-mail-gateway/](https://starlabs.sg/blog/2022/12-multiple-vulnerabilites-in-proxmox-ve--proxmox-mail-gateway/)
To fix CVE-2022-31358 in Proxmox Virtual Environment, update to version v7.2-3 or later.