CVE-2022-42054: XSS

Published Oct 27, 2022
·
Updated

Multiple stored cross-site scripting (XSS) vulnerabilities in GL.iNet GoodCloud IoT Device Management System Version 1.00.220412.00 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Company Name and Description text fields.

Affected Software

1 affected component
gl-inet Goodcloud=1.00.220412.00

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Apply server-side sanitization and output encoding for the Company Name and Description fields to prevent execution of arbitrary web scripts/HTML from crafted payloads (XSS).

    GL.iNet GoodCloud IoT Device Management System Company Name and Description text field handling = Use output encoding / sanitize user-supplied content to prevent injected HTML/JavaScript from being executed
  2. Compensating control

    Mitigate the GL.iNet GoodCloud IoT Device Management System XSS by restricting access to the application so only trusted users can reach the web interface where the Company Name and Description fields are used.

Event History

Oct 27, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the vulnerability ID of this GL.iNet GoodCloud IoT Device Management System vulnerability?

The vulnerability ID of this GL.iNet GoodCloud IoT Device Management System vulnerability is CVE-2022-42054.

2

What is the severity rating of CVE-2022-42054?

The severity rating of CVE-2022-42054 is medium (5.4).

3

How do the multiple stored cross-site scripting (XSS) vulnerabilities impact GL.iNet GoodCloud IoT Device Management System?

The multiple stored cross-site scripting (XSS) vulnerabilities in GL.iNet GoodCloud IoT Device Management System allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Company Name and Description text fields.

4

What is the affected software version of GL.iNet GoodCloud IoT Device Management System vulnerability?

The affected software version of GL.iNet GoodCloud IoT Device Management System vulnerability is 1.00.220412.00.

5

Is there any fix available for the GL.iNet GoodCloud IoT Device Management System vulnerability?

It is recommended to update GL.iNet GoodCloud IoT Device Management System to the latest version available to mitigate the multiple stored cross-site scripting (XSS) vulnerabilities.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203