CVE-2022-39025: e-Excellence Inc. U-Office Force - Reflected XSS
U-Office Force PrintMessage function has insufficient filtering for special characters. An unauthenticated remote attacker can exploit this vulnerability to inject JavaScript and perform XSS (Reflected Cross-Site Scripting) attack.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-39025?
CVE-2022-39025 has a high severity rating due to its potential for remote code execution through XSS attacks.
How do I fix CVE-2022-39025?
To fix CVE-2022-39025, ensure that you update U-Office Force to a version newer than 20.50.7821d which addresses this vulnerability.
What type of attacks can be executed due to CVE-2022-39025?
CVE-2022-39025 is exploitable through reflected Cross-Site Scripting (XSS) attacks that can lead to the injection of malicious JavaScript.
Who is affected by CVE-2022-39025?
CVE-2022-39025 affects users of the U-Office Force software version up to and including 20.50.7821d.
Can CVE-2022-39025 be exploited without authentication?
Yes, CVE-2022-39025 can be exploited by an unauthenticated remote attacker.