Record summary

CVE-2022-41441 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

Multiple cross-site scripting (XSS) vulnerabilities in ReQlogic v11.3 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the POBatch and WaitDuration parameters.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 2, 2025 · Source: CVE List

Proofs of concept

1

Catalogued exploits

ExploitDBReQlogic v11.3 - Reflected Cross-Site Scripting (XSS)ExploitDB exploitby Okan KurtulusNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMReQlogic v11.3 - Cross Site ScriptingCVSS 6.1

ReQlogic v11.3 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the POBatch and WaitDuration parameters.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute malicious scripts in the victim's browser, leading to session hijacking, defacement, or theft of sensitive information.

Remediation

Apply the latest security patches or updates provided by the vendor to fix the XSS vulnerability in ReQlogic v11.3.

WeaknessesCWE-79
Authorsr3Y3r53
Template tagscvecve2022packetstormxssreqlogicvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:reqlogic:reqlogic:11.3:*:*:*:*:*:*:*
Shodan: http.html:"ReQlogic"
Shodan: http.html:"reqlogic"
FOFA: body="reqlogic"

Source: ProjectDiscovery

References

5