CVE-2022-42054: XSS
Multiple stored cross-site scripting (XSS) vulnerabilities in GL.iNet GoodCloud IoT Device Management System Version 1.00.220412.00 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Company Name and Description text fields.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Apply server-side sanitization and output encoding for the Company Name and Description fields to prevent execution of arbitrary web scripts/HTML from crafted payloads (XSS).
GL.iNet GoodCloud IoT Device Management System Company Name and Description text field handling = Use output encoding / sanitize user-supplied content to prevent injected HTML/JavaScript from being executed - Compensating control
Mitigate the GL.iNet GoodCloud IoT Device Management System XSS by restricting access to the application so only trusted users can reach the web interface where the Company Name and Description fields are used.
Event History
Frequently Asked Questions
What is the vulnerability ID of this GL.iNet GoodCloud IoT Device Management System vulnerability?
The vulnerability ID of this GL.iNet GoodCloud IoT Device Management System vulnerability is CVE-2022-42054.
What is the severity rating of CVE-2022-42054?
The severity rating of CVE-2022-42054 is medium (5.4).
How do the multiple stored cross-site scripting (XSS) vulnerabilities impact GL.iNet GoodCloud IoT Device Management System?
The multiple stored cross-site scripting (XSS) vulnerabilities in GL.iNet GoodCloud IoT Device Management System allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Company Name and Description text fields.
What is the affected software version of GL.iNet GoodCloud IoT Device Management System vulnerability?
The affected software version of GL.iNet GoodCloud IoT Device Management System vulnerability is 1.00.220412.00.
Is there any fix available for the GL.iNet GoodCloud IoT Device Management System vulnerability?
It is recommended to update GL.iNet GoodCloud IoT Device Management System to the latest version available to mitigate the multiple stored cross-site scripting (XSS) vulnerabilities.