5.4
CVSSv3

CVE-2022-26088

Published: 10/11/2022 Updated: 15/11/2022
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 0

Vulnerability Summary

An issue exists in BMC Remedy prior to 22.1. Email-based Incident Forwarding allows remote authenticated users to inject HTML (such as an SSRF payload) into the Activity Log by placing it in the To: field. This affects rendering that occurs upon a click in the "number of recipients" field. NOTE: the vendor's position is that "no real impact is demonstrated."

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

bmc remedy it service management suite 20.02

Exploits

BMC Remedy ITSM-Suite version 9110 (2002 in new versioning scheme) suffers from an html injection vulnerability ...