en.wikipedia.org
https://en.wikipedia.org/wiki/H-Sphere CVE-2022-30777
MEDIUMNuclei
parallels h-sphere Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Record summary
CVE-2022-30777 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
Parallels H-Sphere 3.6.1713 allows XSS via the index_en.php from parameter.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jan 29, 2026 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
h-sphereBrowse parallels / h-sphere | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryMEDIUMParallels H-Sphere 3.6.1713 - Cross-Site ScriptingCVSS 6.1
Parallels H-Sphere 3.6.1713 contains a cross-site scripting vulnerability via the index_en.php 'from' parameter.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the victim's browser, leading to session hijacking, defacement, or theft of sensitive information.
Remediation
Apply the latest security patch or upgrade to a newer version of Parallels H-Sphere to mitigate the XSS vulnerability.
WeaknessesCWE-79
Authors3th1c_yuk1
Template tagscvecve2022parallelshspherexssvulnvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:parallels:h-sphere:3.6.2:*:*:*:*:*:*:*
Shodan: title:"h-sphere"
Shodan: http.title:"h-sphere"
Shodan: http.title:"parallels h-sphere"
FOFA: title="h-sphere"
FOFA: title="parallels h-sphere"
Google: intitle:"h-sphere"
Google: intitle:"parallels h-sphere"
https://medium.com/@bhattronit96/cve-2022-30777-45725763ab59 https://en.wikipedia.org/wiki/H-Sphere https://nvd.nist.gov/vuln/detail/CVE-2022-30777 https://medium.com/%40bhattronit96/cve-2022-30777-45725763ab59 https://github.com/ARPSyndicate/cvemon
Source: ProjectDiscovery
References
4medium.com
https://medium.com/%40bhattronit96/cve-2022-30777-45725763ab59 medium.com
https://medium.com/@bhattronit96/cve-2022-30777-45725763ab59 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-30777