Cross-Site Scripting Vulnerability in Parallels H-Sphere
CVE-2022-30777

6.1MEDIUM

Key Information:

Vendor

Parallels

Status
Vendor
CVE Published:
16 May 2022

What is CVE-2022-30777?

The Parallels H-Sphere version 3.6.1713 is vulnerable to a cross-site scripting (XSS) attack through the index_en.php file. Malicious actors can exploit this vulnerability by sending crafted requests that manipulate the input parameters, potentially allowing them to execute arbitrary scripts in the context of a victim's browser. This could lead to unauthorized access to sensitive data or session hijacking. It is crucial for users of this product to address this vulnerability promptly to safeguard their systems.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.