First published: Thu Jul 14 2022(Updated: )
A reflected DOM-Based XSS vulnerability has been discovered in the Help directory of Veeam Management Pack for Microsoft System Center 8.0. This vulnerability could be exploited by an attacker by convincing a legitimate user to visit a crafted URL on a Veeam Management Pack for Microsoft System Center server, allowing for the execution of arbitrary scripts.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Veeam Management Pack | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-32225 is a reflected DOM-Based XSS vulnerability discovered in the Help directory of Veeam Management Pack for Microsoft System Center 8.0.
CVE-2022-32225 can be exploited by convincing a legitimate user to visit a crafted URL on Veeam Management Pack for Microsoft System Center 8.0.
The severity of CVE-2022-32225 is medium with a CVSS score of 6.1.
CVE-2022-32225 affects Veeam Management Pack for Microsoft System Center 8.0.
To fix CVE-2022-32225, it is recommended to apply the security patch provided by Veeam or upgrade to a non-vulnerable version of the software.