CVE-2022-45472

MEDIUM

CAE LearningSpace Enterprise - DOM-Based Cross-Site Scripting via ontouchmove and onpointerup

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2022-45472. PoCs published by nicbrinkley.

AI-analyzed exploit summary This repository contains a writeup describing a DOM-based XSS vulnerability (CVE-2022-45472) in CAE Learning Space Enterprise with Intuity License (Image Version: 267r, Patch Level: 639). The writeup details the discovery process, impact, and recommendations but does not include exploit code.

Description

CAE LearningSpace Enterprise (with Intuity License) image 267r patch 639 allows DOM XSS, related to ontouchmove and onpointerup.

Exploits (1)

nomisec WRITEUP 1 stars
by nicbrinkley · poc
https://github.com/nicbrinkley/CVE-2022-45472

This repository contains a writeup describing a DOM-based XSS vulnerability (CVE-2022-45472) in CAE Learning Space Enterprise with Intuity License (Image Version: 267r, Patch Level: 639). The writeup details the discovery process, impact, and recommendations but does not include exploit code.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: CAE Learning Space Enterprise with Intuity License (Image Version: 267r, Patch Level: 639)
No auth needed
Prerequisites: Access to the vulnerable application
MITRE ATT&CK
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2

Scores

CVSS v3 5.4
EPSS 0.0052
EPSS Percentile 40.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
caehealthcare/learningspace_enterprise image_267r patch_639
Published Nov 23, 2022
Tracked Since Feb 18, 2026