SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-3245

HTML injection attack is closely related to Cross-site Scripting (XSS).

MEDIUM 6.1EPSS 0.61%

Does this matter?

Lower severity and a low EPSS score (0.61%). Track it; it rarely justifies an emergency change on its own.

Description

HTML injection attack is closely related to Cross-site Scripting (XSS). HTML injection uses HTML to deface the page. XSS, as the name implies, injects JavaScript into the page. Both attacks exploit insufficient validation of user input.

CVSS 3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
0.61% probability · 47th percentile
CISA KEV
Not listed
Weakness
CWE-94, CWE-79
Affected
microweber/microweber
Source
security@huntr.dev

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.