Cross-Site Scripting Vulnerability in Artica Proxy by Artica
CVE-2022-37153

6.1MEDIUM

Key Information:

Vendor

Articatech

Vendor
CVE Published:
24 August 2022

Badges

๐Ÿ‘พ Exploit Exists

What is CVE-2022-37153?

A security flaw in Artica Proxy 4.30.000000 allows attackers to execute cross-site scripting (XSS) through a maliciously crafted request to the password parameter in the login script (/fw.login.php). This vulnerability can potentially lead to unauthorized actions and data exposure. It is crucial for users of this version to apply necessary patches and secure their applications to mitigate the risk of exploitation.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.