Record summary

CVE-2022-30777 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

Parallels H-Sphere 3.6.1713 allows XSS via the index_en.php from parameter.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jan 29, 2026 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryMEDIUMParallels H-Sphere 3.6.1713 - Cross-Site ScriptingCVSS 6.1

Parallels H-Sphere 3.6.1713 contains a cross-site scripting vulnerability via the index_en.php 'from' parameter.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the victim's browser, leading to session hijacking, defacement, or theft of sensitive information.

Remediation

Apply the latest security patch or upgrade to a newer version of Parallels H-Sphere to mitigate the XSS vulnerability.

WeaknessesCWE-79
Authors3th1c_yuk1
Template tagscvecve2022parallelshspherexssvulnvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:parallels:h-sphere:3.6.2:*:*:*:*:*:*:*
Shodan: title:"h-sphere"
Shodan: http.title:"h-sphere"
Shodan: http.title:"parallels h-sphere"
FOFA: title="h-sphere"
FOFA: title="parallels h-sphere"
Google: intitle:"h-sphere"
Google: intitle:"parallels h-sphere"

Source: ProjectDiscovery

References

4