CVE-2022-23397

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
04/03/2022
Last modified:
29/10/2024

Description

The Cedar Gate EZ-NET portal 6.5.5 6.8.0 Internet portal has a call to display messages to users which does not properly sanitize data sent in through a URL parameter. This leads to a Reflected Cross-Site Scripting vulnerability. NOTE: the vendor disputes this because the ado.im reference has "no clear steps of reproduction."

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cedargate:ez-net_portal:6.5.5:*:*:*:*:*:*:*
cpe:2.3:a:cedargate:ez-net_portal:6.6.3:*:*:*:*:*:*:*
cpe:2.3:a:cedargate:ez-net_portal:6.7.0:*:*:*:*:*:*:*
cpe:2.3:a:cedargate:ez-net_portal:6.8.0:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools