github.com
https://github.com/Docker-droid/H3C_SSL_VPN_XSS CVE-2022-35416
MEDIUMNuclei
H3C SSL VPN <=2022-07-10 - Cross-Site Scripting
Record summary
CVE-2022-35416 has a selected CVSS score of 6.1 (medium); EIP currently links 1 repository PoC and 1 Nuclei template.
Proofs of concept
1Repository PoCs
GitHubsafe3s/CVE-2022-35416Repository PoCby safe3sStars: 7Not analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMH3C SSL VPN <=2022-07-10 - Cross-Site ScriptingCVSS 6.1
H3C SSL VPN 2022-07-10 and prior contains a cookie-based cross-site scripting vulnerability in wnm/login/login.json svpnlang.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the context of the victim's browser, potentially leading to session hijacking, data theft, or other malicious activities.
Remediation
Apply the latest security patch or upgrade to a version of H3C SSL VPN that is not affected by this vulnerability.
WeaknessesCWE-79
Authors0x240x23elu
Template tagscvecve2022xssvpnh3cvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:h3c:ssl_vpn:*:*:*:*:*:*:*:*
Shodan: http.html_hash:510586239
https://github.com/advisories/GHSA-9x76-78gc-r3m9 https://github.com/Docker-droid/H3C_SSL_VPN_XSS https://nvd.nist.gov/vuln/detail/CVE-2022-35416 https://github.com/ARPSyndicate/kenzer-templates https://github.com/bughunter0xff/recon-scanner
Source: ProjectDiscovery
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-35416