Record summary

CVE-2022-24384 has a selected CVSS score of 8.8 (high); EIP currently links 1 Nuclei template.

Description

Cross-site Scripting (XSS) vulnerability in SmarterTools SmarterTrack This issue affects: SmarterTools SmarterTrack 100.0.8019.14010.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated May 24, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unknown

CVE List100.x to < Build 8075affected
Before 100.0.8075affected

Nuclei templates

1
ProjectDiscoveryMEDIUMSmarterTools SmarterTrack - Cross-Site ScriptingCVSS 6.1

Cross-site Scripting (XSS) vulnerability in SmarterTools SmarterTrack This issue affects: SmarterTools SmarterTrack 100.0.8019.14010.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the context of the victim's browser, potentially leading to session hijacking, defacement, or theft of sensitive information.

Remediation

Apply the latest security patches or updates provided by SmarterTools to fix this vulnerability.

WeaknessesCWE-79
AuthorsE1A
Template tagscvecve2022xsssmartertracksmartertoolsvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:smartertools:smartertrack:*:*:*:*:*:*:*:*
Shodan: http.favicon.hash:1410071322
FOFA: icon_hash=1410071322

Source: ProjectDiscovery

References

3