Stored XSS Vulnerability in Incapptic Connect by Ivanti
CVE-2022-22571

4.8MEDIUM

Key Information:

Vendor
Ivanti
Vendor
CVE Published:
11 April 2022

Summary

An authenticated user with high privileges can exploit a stored XSS vulnerability in Incapptic Connect due to improper output encoding. This flaw allows an attacker to inject malicious scripts that could execute in the browser of other users who access compromised data. This vulnerability affects all current versions of the product, posing a risk to user data and application integrity.

Affected Version(s)

Ivanti Incapptic Connect A workaround has been published to fix this issue

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.