CVE-2022-3804

MEDIUM

eolink apinto-dashboard - Cross-Site Scripting via Login Callback Parameter

Title source: llm
STIX 2.1

Description

A vulnerability was found in eolinker apinto-dashboard. It has been classified as problematic. Affected is an unknown function of the file /login. The manipulation of the argument callback leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-212640.

References (3)

Core 3
Core References
Exploit, Third Party Advisory
https://c2.im5i.com/2022/11/01/XrTL4.png
Exploit, Third Party Advisory
https://c2.im5i.com/2022/11/01/Xrjjd.png
Third Party Advisory
https://vuldb.com/?id.212640

Scores

CVSS v3 4.3
EPSS 0.0058
EPSS Percentile 43.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79 CWE-707
Status published
Products (1)
eolink/apinto-dashboard
Published Nov 01, 2022
Tracked Since Feb 18, 2026