CVE-2022-37461
Multiple cross-site scripting (XSS) vulnerabilities in Canon Medical Vitrea View 7.x before 7.7.6 allow remote attackers to inject arbitrary web script or HTML via (1) the input after the error subdirectory to the /vitrea-view/error/ subdirectory, or…
Does this matter?
Lower severity and a low EPSS score (1.00%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Canon Medical Vitrea View 7.x before 7.7.6 allow remote attackers to inject arbitrary web script or HTML via (1) the input after the error subdirectory to the /vitrea-view/error/ subdirectory, or the (2) groupID, (3) offset, or (4) limit parameter to an Administrative Panel (Group and Users) page. There is a risk of an attacker retrieving patient information.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 1.00% probability · 61th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- canon/medical vitrea view
- Source
- cve@mitre.org
References
- https://www.trustwave.com/en-us/resources/security-resources/security-advisories/?fid=30693Exploit, Third Party Advisory
- https://www.vitalimages.com/customer-success-support-program/vital-images-software-security-updates/Vendor Advisory
- https://www.vitalimages.com/vitrea-vision/vitrea-view/Product, Vendor Advisory
- https://www.trustwave.com/en-us/resources/security-resources/security-advisories/?fid=30693Exploit, Third Party Advisory
- https://www.vitalimages.com/customer-success-support-program/vital-images-software-security-updates/Vendor Advisory
- https://www.vitalimages.com/vitrea-vision/vitrea-view/Product, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.