CVE-2022-41441
ReQlogic v11.3 - Reflected Cross-Site Scripting (XSS)
Record summary
CVE-2022-41441 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Description
Multiple cross-site scripting (XSS) vulnerabilities in ReQlogic v11.3 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the POBatch and WaitDuration parameters.
Exploitation context
Proofs of concept
1Catalogued exploits
ExploitDBReQlogic v11.3 - Reflected Cross-Site Scripting (XSS)ExploitDB exploitby Okan KurtulusNot analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMReQlogic v11.3 - Cross Site ScriptingCVSS 6.1
ReQlogic v11.3 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the POBatch and WaitDuration parameters.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute malicious scripts in the victim's browser, leading to session hijacking, defacement, or theft of sensitive information.
Remediation
Apply the latest security patches or updates provided by the vendor to fix the XSS vulnerability in ReQlogic v11.3.
Source: ProjectDiscovery