Record summary

CVE-2022-35416 has a selected CVSS score of 6.1 (medium); EIP currently links 1 repository PoC and 1 Nuclei template.

Description

H3C SSL VPN through 2022-07-10 allows wnm/login/login.json svpnlang cookie XSS.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1
Nuclei templates
1

Proofs of concept

1

Repository PoCs

GitHubsafe3s/CVE-2022-35416Repository PoCby safe3sStars: 7Not analyzed1 file

361 B

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMH3C SSL VPN <=2022-07-10 - Cross-Site ScriptingCVSS 6.1

H3C SSL VPN 2022-07-10 and prior contains a cookie-based cross-site scripting vulnerability in wnm/login/login.json svpnlang.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the context of the victim's browser, potentially leading to session hijacking, data theft, or other malicious activities.

Remediation

Apply the latest security patch or upgrade to a version of H3C SSL VPN that is not affected by this vulnerability.

WeaknessesCWE-79
Authors0x240x23elu
Template tagscvecve2022xssvpnh3cvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:h3c:ssl_vpn:*:*:*:*:*:*:*:*
Shodan: http.html_hash:510586239

Source: ProjectDiscovery

References

2