Quaonos Schema ST4 example templates prone to XSS
Published Dec 14, 2022
6.1
MEDIUMCVSS 3.1
EPSS 0.47%
Description
Quanos "SCHEMA ST4" example web templates in version Bootstrap 2019 v2/2021 v1/2022 v1/2022 SP1 v1 or below are prone to JavaScript injection allowing a remote attacker to hijack existing sessions to e.g. other web services in the same environment or execute scripts in the users browser environment. The affected script is '*-schema.js'.
Affected products
-
- Version 1StatusaffectedConstraints<=2
- Version 1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Quanos | Schema ST4 example web templates | unaffected |
|
Configuration 1
Running on/with
- n/a
Configuration 2
Running on/with
- n/a
Configuration 3
Running on/with
- n/a
Configuration 4
Running on/with
- n/a
Configuration 5
Running on/with
- n/a
Configuration 6
- ≤ 1.16.0
Running on/with
- n/a
Configuration 7
- ≤ 1.16.0
Running on/with
- n/a
Configuration 8
- ≤ 1.16.0
Running on/with
- n/a
Configuration 9
- ≤ 1.16.0
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (1)
- https://cert.vde.com/de/advisories/VDE-2022-056/ Third Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://cert.vde.com/de/advisories/VDE-2022-056/ | Third Party Advisory |
Change history (0)
No recorded changes yet.