CVE-2022-39026: e-Excellence Inc. U-Office Force - Stored XSS
U-Office Force UserDefault page has insufficient filtering for special characters in the HTTP header fields. A remote attacker with general user privilege can exploit this vulnerability to inject JavaScript and perform XSS (Stored Cross-Site Scripting) attack.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-39026?
CVE-2022-39026 is classified as a medium severity vulnerability due to its potential for XSS attacks.
How do I fix CVE-2022-39026?
To fix CVE-2022-39026, ensure that input validation and filtering for special characters in HTTP headers are implemented properly.
What type of vulnerability is CVE-2022-39026?
CVE-2022-39026 is a Stored Cross-Site Scripting (XSS) vulnerability that allows an attacker to inject JavaScript code.
Who is affected by CVE-2022-39026?
CVE-2022-39026 affects users of Edetw U-office Force versions up to and including 20.50.7821d.
Can CVE-2022-39026 be exploited remotely?
Yes, CVE-2022-39026 can be exploited remotely by an attacker with general user privileges.