CVE-2022-1293

MEDIUM

Thales Citadel < 7.1.2 - Cross-Site Scripting via Script Tag Neutralization Bypass

Title source: llm
STIX 2.1

Description

The embedded neutralization of Script-Related HTML Tag, was by-passed in the case of some extra conditions.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_misc
https://www.ercom.com/security-updates

Scores

CVSS v3 5.7
EPSS 0.0039
EPSS Percentile 31.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

Details

CWE
CWE-80 CWE-79
Status published
Products (1)
thalesgroup/citadel < 7.1.2
Published Aug 02, 2022
Tracked Since Feb 18, 2026