CVE-2022-34007
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
07/07/2022
Last modified:
26/10/2022
Description
EQS Integrity Line Professional through 2022-07-01 allows a stored XSS via a crafted whistleblower entry.
Impact
Base Score 3.x
6.10
Severity 3.x
MEDIUM
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:eqs:integrity_line:*:*:*:*:professional:*:*:* | 2022-07-01 (including) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://eusanctions.integrityline.com
- https://packetstormsecurity.com/files/167706/EQS-Integrity-Line-Cross-Site-Scripting-Information-Disclosure.html
- https://seclists.org/fulldisclosure/2022/Jul/1
- https://whistleblowingnetwork.org/Our-Work/Spotlight/Stories/The-Pitfalls-of-Closed-Source-Whistleblowing-Softw
- https://www.integrityline.com/
- https://www.ush.it/team/ush/advisory-eqs-integrity-line/eqs_integrity_line.txt



