Stored XSS Vulnerability in OPSWAT MetaDefender ICAP Server
CVE-2022-40778

5.4MEDIUM

Key Information:

Vendor

Opswat

Vendor
CVE Published:
19 September 2022

What is CVE-2022-40778?

A stored Cross-Site Scripting (XSS) vulnerability exists in OPSWAT MetaDefender ICAP Server prior to version 4.13.0. This flaw allows attackers to execute arbitrary JavaScript or HTML code by manipulating the blocked page response. Exploiting this vulnerability could lead to unauthorized actions and data exposure, emphasizing the need for timely updates and security practices.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.