Record summary

CVE-2022-37153 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

An issue was discovered in Artica Proxy 4.30.000000. There is a XSS vulnerability via the password parameter in /fw.login.php.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Sep 16, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryMEDIUMArtica Proxy 4.30.000000 - Cross-Site ScriptingCVSS 6.1

Artica Proxy 4.30.000000 contains a cross-site scripting vulnerability via the password parameter in /fw.login.php.

Impact

Attackers can inject malicious JavaScript through the password parameter in the Artica Proxy login page that reflects back to users, potentially stealing credentials or session tokens when victims submit the login form.

Remediation

Upgrade to a patched version of Artica Proxy or apply the vendor-supplied patch to mitigate the vulnerability.

WeaknessesCWE-79
Authorsarafatansari
Template tagscvecve2022xssarticaarticatechvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:articatech:artica_proxy:4.30.000000:*:*:*:*:*:*:*
Shodan: http.html:"Artica"
Shodan: http.html:"artica"
FOFA: body="artica"

Source: ProjectDiscovery

References

2