CVE-2022-28363
reprisesoftware reprise_license_manager Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Record summary
CVE-2022-28363 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability (XSS) in the /goform/login_process username parameter via GET. No authentication is required.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jun 5, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
reprise_license_managerBrowse reprisesoftware / reprise_license_manager | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryMEDIUMReprise License Manager 14.2 - Cross-Site ScriptingCVSS 6.1
Reprise License Manager 14.2 contains a reflected cross-site scripting vulnerability in the /goform/login_process 'username' parameter via GET, whereby no authentication is required.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim's browser, leading to potential session hijacking, defacement, or theft of sensitive information.
Remediation
Upgrade to a patched version of Reprise License Manager or apply the vendor-supplied patch to mitigate this vulnerability.
Source: ProjectDiscovery