CVE-2022-46381
niceforyou linear_emerge_e3_access_control_firmware Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Record summary
CVE-2022-46381 has a selected CVSS score of 6.1 (medium); EIP currently links 1 repository PoC and 1 Nuclei template.
Description
Certain Linear eMerge E3-Series devices are vulnerable to XSS via the type parameter (e.g., to the badging/badge_template_v0.php component). This affects 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e.
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
linear_emerge_e3_access_control_firmwareBrowse niceforyou / linear_emerge_e3_access_control_firmware | VulnCheck | Version data not supplied | |
Proofs of concept
1Repository PoCs
GitHubamitlttwo/CVE-2022-46381Repository PoCby amitlttwoStars: 0Not analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMLinear eMerge E3-Series - Cross-Site ScriptingCVSS 6.1
Linear eMerge E3-Series devices contain a cross-site scripting vulnerability via the type parameter, e.g., to the badging/badge_template_v0.php component. An attacker can inject arbitrary script in the browser of an unsuspecting user in the context of the affected site and thus steal cookie-based authentication credentials and launch other attacks. This affects versions 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the context of a victim's browser, leading to session hijacking, defacement, or theft of sensitive information.
Remediation
Apply the latest security patch or update provided by the vendor to fix the XSS vulnerability in the Linear eMerge E3-Series.
Source: ProjectDiscovery