CVE-2023-45222: Westermo Lynx Cross-site Scripting
Published Feb 6, 2024
·Updated
An attacker with access to the web application that has the vulnerable software could introduce arbitrary JavaScript by injecting a cross-site scripting payload into the "autorefresh" parameter.
Affected Software
2 affected components
All of the following
Westermo L206-f2g Firmware=4.24
Westermo L206-f2g
Event History
Feb 6, 2024
CVE Published
via MITRE·09:44 PM
Data Sourced
via MITRE·09:44 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-45222?
CVE-2023-45222 is classified as a medium-severity vulnerability due to its potential to allow cross-site scripting attacks.
2
How do I fix CVE-2023-45222?
To remediate CVE-2023-45222, update the Westermo L206-f2g firmware to the latest version beyond 4.24 that addresses this issue.
3
What is affected by CVE-2023-45222?
CVE-2023-45222 affects Westermo L206-f2g firmware version 4.24.
4
What type of attack does CVE-2023-45222 allow?
CVE-2023-45222 enables attackers to execute arbitrary JavaScript through a cross-site scripting payload via the 'autorefresh' parameter.
5
Who is at risk from CVE-2023-45222?
Web applications using vulnerable versions of Westermo L206-f2g firmware are at risk from CVE-2023-45222.