CVE-2022-22804
Expert Analysis
Professional remediation guidance
Get tailored security recommendations from our analyst team for CVE-2022-22804. We'll provide specific mitigation strategies based on your environment and risk profile.
Description
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could allow an authenticated attacker to view data, change settings, or impact availability of the software when the user visits a page containing the injected payload. Affected Product: EcoStruxure Power Monitoring Expert (Versions 2020 and prior)
Available Exploits
Related News
GitHub Security Advisories
Community-driven vulnerability intelligence from GitHub
Advisory Details
CVSS Scoring
CVSS Score
References
Advisory provided by GitHub Security Advisory Database. Published: February 11, 2022, Modified: February 11, 2022