CVE-2022-29034
Description
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). An error message pop up window in the web interface of the affected application does not prevent injection of JavaScript code. This could allow attackers to perform reflected cross-site scripting (XSS) attacks.
References
PatchVendor Advisory
ExploitMailing ListThird Party Advisory
ExploitMailing ListThird Party Advisory
CvssV3 impact
Could not find any metrics
CvssV2 impact
AccessComplexity | MEDIUM |
ConfidentialityImpact | NONE |
AvailabilityImpact | NONE |
IntegrityImpact | PARTIAL |
BaseScore | 4.300000190734863 |
VectorString | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Version | 2.0 |
AccessVector | NETWORK |
Authentication | NONE |