First published: Wed Nov 09 2022(Updated: )
VMware Workspace ONE Assist prior to 22.10 contains a Reflected cross-site scripting (XSS) vulnerability. Due to improper user input sanitization, a malicious actor with some user interaction may be able to inject javascript code in the target user's window.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware Workspace ONE Assist | <22.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-31688 is categorized as a moderate severity vulnerability due to its reflected cross-site scripting risks.
To fix CVE-2022-31688, upgrade to VMware Workspace ONE Assist version 22.10 or later.
CVE-2022-31688 allows for reflected cross-site scripting attacks that can potentially inject malicious JavaScript into a user's window.
Users of VMware Workspace ONE Assist versions prior to 22.10 are at risk from CVE-2022-31688.
Reflected cross-site scripting in CVE-2022-31688 refers to the exploitation that occurs when injected scripts are executed in the user's browser due to insufficient input sanitization.