5.4
CVSSv3

CVE-2022-24654

Published: 15/08/2022 Updated: 26/10/2022
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 0

Vulnerability Summary

Authenticated stored cross-site scripting (XSS) vulnerability in "Field Server Address" field in INTELBRAS ATA 200 Firmware 74.19.10.21 allows malicious users to inject JavaScript code through a crafted payload.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

intelbras ata_200_firmware 74.19.10.21

Github Repositories

PoC for CVE-2022-24654

CVE-2022-24654 PoC of CVE-2022-24654 - INTELBRAS ATA 200 Firmware 74191021 Authenticated stored Cross Site Scripting Steps to Reproduce: Log in the equipment via your web browser Go to Management > Syslog In the "Field Server Address" inject the payload "-prompt("XSS")-" Click Save Exploit!