mirror of
https://github.com/0xMarcio/cve.git
synced 2025-12-16 20:27:21 +00:00
19 lines
783 B
Markdown
19 lines
783 B
Markdown
|
|
### [CVE-2022-48111](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-48111)
|
||
|
|

|
||
|
|

|
||
|
|

|
||
|
|
|
||
|
|
### Description
|
||
|
|
|
||
|
|
A cross-site scripting (XSS) vulnerability in the check_login function of SIPE s.r.l WI400 between version 8 and 11 included allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the f parameter.
|
||
|
|
|
||
|
|
### POC
|
||
|
|
|
||
|
|
#### Reference
|
||
|
|
- https://devisions.github.io/blog/cve-2022-48111
|
||
|
|
- https://labs.yarix.com/2023/02/siri-wi400-xss-on-login-page-cve-2022-48111/
|
||
|
|
|
||
|
|
#### Github
|
||
|
|
No PoCs found on GitHub currently.
|
||
|
|
|