Reflected Cross-Site Scripting Vulnerability in Proxmox Virtual Environment
CVE-2022-31358
9CRITICAL
What is CVE-2022-31358?
The Proxmox Virtual Environment contains a reflected cross-site scripting (XSS) vulnerability affecting versions prior to 7.2-3. This vulnerability allows remote attackers to execute arbitrary web scripts or HTML code through non-existent API endpoints located under the path /api2/html/. Successful exploitation can compromise the integrity of web applications, leading to unauthorized access and data exposure.
