Reflective XSS Vulnerability in SAUTER Controls ModuWeb Firmware
CVE-2022-40190

8.8HIGH

Key Information:

Status
Vendor
CVE Published:
31 October 2022

What is CVE-2022-40190?

SAUTER Controls moduWeb firmware version 2.7.1 is susceptible to reflective cross-site scripting (XSS) due to inadequate sanitization of request strings. This vulnerability allows attackers to inject harmful JavaScript code, which can execute in the browsers of users accessing the affected application. Consequently, attackers could gain unauthorized access to sensitive information, including user credentials and personal data.

Affected Version(s)

moduWeb firmware Version 2.7.1

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ithaca Labs of Odyssey Cyber Security reported this vulnerability.
.