CVE-2022-37153
articatech artica_proxy Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Record summary
CVE-2022-37153 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
An issue was discovered in Artica Proxy 4.30.000000. There is a XSS vulnerability via the password parameter in /fw.login.php.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Sep 16, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
artica_proxyBrowse articatech / artica_proxy | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryMEDIUMArtica Proxy 4.30.000000 - Cross-Site ScriptingCVSS 6.1
Artica Proxy 4.30.000000 contains a cross-site scripting vulnerability via the password parameter in /fw.login.php.
Impact
Attackers can inject malicious JavaScript through the password parameter in the Artica Proxy login page that reflects back to users, potentially stealing credentials or session tokens when victims submit the login form.
Remediation
Upgrade to a patched version of Artica Proxy or apply the vendor-supplied patch to mitigate the vulnerability.
Source: ProjectDiscovery