Reflected Cross-Site Scripting in Danfoss AK-EM100
CVE-2023-22582
9CRITICAL
What is CVE-2023-22582?
The Danfoss AK-EM100 web application is susceptible to reflected Cross-Site Scripting (XSS) attacks, allowing malicious actors to inject harmful scripts into web pages viewed by users. This vulnerability arises when user input is not properly validated, potentially leading to unauthorized actions, data theft, or session hijacking. Organizations using this product should consider immediate mitigative steps to secure their applications against such attacks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
AK-EM100 < 2.2.0.12
References
CVSS V3.1
Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Jony Schats (Hackdefense)
Stan Plasmeijer (Hackdefense)
Max van der Horst (DIVD)
