CVE-2022-3193: XSS
An HTML injection/reflected Cross-site scripting (XSS) vulnerability was found in the ovirt-engine. A parameter "errordescription" fails to sanitize the entry, allowing the vulnerability to trigger on the Windows Service Accounts home pages.
Other sources
An HTML injection/reflected XSS vulnerability is found in the ovirt-engine. A parameter "errordescription" fails to sanitize the entry allowing the vulnerability to trigger on the Windows Service Accounts home pages. Several filtering and escaping techniques can be used to mitigate these input validation vulnerabilities.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-3193.
What is the severity of CVE-2022-3193?
The severity of CVE-2022-3193 is high with a severity value of 6.1.
Which software is affected by CVE-2022-3193?
The ovirt-engine software version 4.3.0 is affected by CVE-2022-3193.
What is the CWE ID of CVE-2022-3193?
The CWE IDs of CVE-2022-3193 are 79 and 20.
Are there any references available for CVE-2022-3193?
Yes, you can find references for CVE-2022-3193 at the following URLs: [Reference 1](https://access.redhat.com/security/cve/cve-2022-3193), [Reference 2](https://bugzilla.redhat.com/show_bug.cgi?id=2126353).