CVE-2022-31688: XSS
VMware Workspace ONE Assist prior to 22.10 contains a Reflected cross-site scripting (XSS) vulnerability. Due to improper user input sanitization, a malicious actor with some user interaction may be able to inject javascript code in the target user's window.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-31688?
CVE-2022-31688 is categorized as a moderate severity vulnerability due to its reflected cross-site scripting risks.
How do I fix CVE-2022-31688?
To fix CVE-2022-31688, upgrade to VMware Workspace ONE Assist version 22.10 or later.
What types of attacks are possible with CVE-2022-31688?
CVE-2022-31688 allows for reflected cross-site scripting attacks that can potentially inject malicious JavaScript into a user's window.
Who is affected by CVE-2022-31688?
Users of VMware Workspace ONE Assist versions prior to 22.10 are at risk from CVE-2022-31688.
What does reflected cross-site scripting mean in the context of CVE-2022-31688?
Reflected cross-site scripting in CVE-2022-31688 refers to the exploitation that occurs when injected scripts are executed in the user's browser due to insufficient input sanitization.