Back

MEDIUM

Quaonos Schema ST4 example templates prone to XSS

Published Dec 14, 2022

Description

Quanos "SCHEMA ST4" example web templates in version Bootstrap 2019 v2/2021 v1/2022 v1/2022 SP1 v1 or below are prone to JavaScript injection allowing a remote attacker to hijack existing sessions to e.g. other web services in the same environment or execute scripts in the users browser environment. The affected script is '*-schema.js'.

Affected products

Remediation

No remediation recorded yet.

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner CERTVDE
Published Dec 14, 2022
Updated Apr 17, 2025
Reserved Sep 1, 2022
CISA Vulnrichment
Updated Apr 17, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a