← Volver a CVEs
CVE-2022-24692
MEDIUM5.4
Descripcion
An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. The new menu option within the general Parameters page is vulnerable to stored XSS. The attacker can create a menu option, make it visible to every application user, and conduct session hijacking, account takeover, or malicious code delivery, with the final goal of achieving client-side code execution.
Detalles CVE
Puntuacion CVSS v3.15.4
SeveridadMEDIUM
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosLOW
Interaccion usuarioREQUIRED
Publicado7/18/2022
Ultima modificacion11/21/2024
Fuentenvd
Avistamientos honeypot0
Productos afectados
dsk:dsknet
Debilidades (CWE)
CWE-79
Referencias
https://dsk.lu/fr/produits/temps-de-presence(cve@mitre.org)
https://dsk.lu/fr/produits/temps-de-presence(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/post-cyberlabs/CVE-Advisory/blob/main/CVE-2022-24688-92.pdf(af854a3a-2127-422b-91ae-364da2661108)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.