CVE-2022-40711: XSS
Published Jan 1, 2023
·Updated
PrimeKey EJBCA 7.9.0.2 Community allows stored XSS in the End Entity section. A user with the RA Administrator role can inject an XSS payload to target higher-privilege users.
Affected Software
1 affected component
PrimeKey EJBCA=7.9.0.2
Event History
Jan 1, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-40711?
CVE-2022-40711 has a high severity rating due to its potential for stored cross-site scripting (XSS) attacks.
2
How do I fix CVE-2022-40711?
To fix CVE-2022-40711, update the EJBCA software to the latest version that addresses this vulnerability.
3
Who is affected by CVE-2022-40711?
Users with the RA Administrator role in PrimeKey EJBCA 7.9.0.2 Community are specifically affected by CVE-2022-40711.
4
What type of vulnerability is CVE-2022-40711?
CVE-2022-40711 is a stored cross-site scripting (XSS) vulnerability.
5
What can attackers do with CVE-2022-40711?
Attackers can inject malicious scripts that target higher-privilege users within the application due to CVE-2022-40711.