6.1
CVSSv3

CVE-2022-31798

Published: 25/08/2022 Updated: 08/08/2023
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Nortek Linear eMerge E3-Series 0.32-07p devices are vulnerable to /card_scan.php?CardFormatNo= XSS with session fixation (via PHPSESSID) when they are chained together. This would allow an malicious user to take over an admin account or a user account.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

nortekcontrol emerge_e3_firmware

Exploits

Nortek Linear eMerge E3-Series version 032-07p suffers from a vulnerability where session fixation tied with cross site scripting can allow for account takeover ...

Github Repositories

CVE-2022-31798 Proof of Concept

CVE-2022-31798 Exploit Title: Nortek Linear eMerge E3-Series - account takeover