Cross-Site Scripting Vulnerability in Parallels H-Sphere
CVE-2022-30777
6.1MEDIUM
What is CVE-2022-30777?
The Parallels H-Sphere version 3.6.1713 is vulnerable to a cross-site scripting (XSS) attack through the index_en.php
file. Malicious actors can exploit this vulnerability by sending crafted requests that manipulate the input parameters, potentially allowing them to execute arbitrary scripts in the context of a victim's browser. This could lead to unauthorized access to sensitive data or session hijacking. It is crucial for users of this product to address this vulnerability promptly to safeguard their systems.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved