Record summary

CVE-2022-46381 has a selected CVSS score of 6.1 (medium); EIP currently links 1 repository PoC and 1 Nuclei template.

Description

Certain Linear eMerge E3-Series devices are vulnerable to XSS via the type parameter (e.g., to the badging/badge_template_v0.php component). This affects 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Nov 26, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
1
Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 22, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

linear_emerge_e3_access_control_firmware

Browse niceforyou / linear_emerge_e3_access_control_firmware
VulnCheckVersion data not supplied

Proofs of concept

1

Repository PoCs

GitHubamitlttwo/CVE-2022-46381Repository PoCby amitlttwoStars: 0Not analyzed1 file

16 B

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMLinear eMerge E3-Series - Cross-Site ScriptingCVSS 6.1

Linear eMerge E3-Series devices contain a cross-site scripting vulnerability via the type parameter, e.g., to the badging/badge_template_v0.php component. An attacker can inject arbitrary script in the browser of an unsuspecting user in the context of the affected site and thus steal cookie-based authentication credentials and launch other attacks. This affects versions 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the context of a victim's browser, leading to session hijacking, defacement, or theft of sensitive information.

Remediation

Apply the latest security patch or update provided by the vendor to fix the XSS vulnerability in the Linear eMerge E3-Series.

WeaknessesCWE-79
Authorsarafatansari
Template tagscvecve2022xssemergelinearniceforyouvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:o:niceforyou:linear_emerge_e3_access_control_firmware:0.32-07e:*:*:*:*:*:*:*
Shodan: http.html:"Linear eMerge"
Shodan: http.html:"linear emerge"
FOFA: body="linear emerge"

Source: ProjectDiscovery

References

2