CVE-2022-24432
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
10/03/2022
Last modified:
16/03/2022
Description
Persistent cross-site scripting (XSS) in the web interface of ipDIO allows an authenticated remote attacker to introduce arbitrary JavaScript by injecting an XSS payload into specific fields. The XSS payload will be executed when a legitimate user attempts to upload, copy, download, or delete an existing configuration (Administrative Services).
Impact
Base Score 3.x
5.40
Severity 3.x
MEDIUM
Base Score 2.0
3.50
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:ipcomm:ipdio_firmware:3.9:*:*:*:*:*:*:* | ||
| cpe:2.3:h:ipcomm:ipdio:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



