CVE-2022-50802
ETAP Safety Manager 1.0.0.32 contains a cross-site scripting vulnerability in the 'action' GET parameter that allows unauthenticated attackers to inject malicious HTML and JavaScript.
Does this matter?
Lower severity and a low EPSS score (0.35%). Track it; it rarely justifies an emergency change on its own.
Description
ETAP Safety Manager 1.0.0.32 contains a cross-site scripting vulnerability in the 'action' GET parameter that allows unauthenticated attackers to inject malicious HTML and JavaScript. Attackers can craft specially formed requests to execute arbitrary scripts in victim browser sessions, potentially stealing credentials or performing unauthorized actions.
- CVSS 4.0
- 5.1 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.35% probability · 28th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- etaplighting/etap safety manager
- Source
- disclosure@vulncheck.com
References
- https://cxsecurity.com/issue/WLB-2022090031Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/235743Third Party Advisory
- https://packetstormsecurity.com/files/168339/Third Party Advisory
- https://www.etaplighting.com/Product, US Government Resource
- https://www.vulncheck.com/advisories/etap-safety-manager-unauthenticated-reflected-cross-site-scripting-via-action-parameterThird Party Advisory
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5711.phpThird Party Advisory
- https://cxsecurity.com/issue/WLB-2022090031Third Party Advisory
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5711.phpThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.