CVE-2022-39834: XSS
Published Nov 17, 2022
·Updated
A stored XSS vulnerability was discovered in adminweb/ra/viewendentity.jsp in PrimeKey EJBCA through 7.9.0.2. A low-privilege user can store JavaScript in order to exploit a higher-privilege user.
Affected Software
1 affected component
Keyfactor Primekey Ejbca<=7.9.0.2
Event History
Nov 17, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2022-39834?
CVE-2022-39834 is a stored XSS vulnerability that was discovered in adminweb/ra/viewendentity.jsp in PrimeKey EJBCA through 7.9.0.2.
2
How does CVE-2022-39834 affect PrimeKey EJBCA?
CVE-2022-39834 affects PrimeKey EJBCA versions up to and including 7.9.0.2.
3
What is the severity of CVE-2022-39834?
CVE-2022-39834 has a severity rating of 5.4, which is considered medium.
4
What is the impact of CVE-2022-39834?
CVE-2022-39834 allows a low-privilege user to store JavaScript and exploit a higher-privilege user.
5
How can CVE-2022-39834 be fixed?
To fix CVE-2022-39834, it is recommended to upgrade to a version of PrimeKey EJBCA higher than 7.9.0.2.