2022-06-30 19:00:46 +00:00
{
"CVE_data_meta" : {
2022-07-05 10:38:14 -05:00
"ASSIGNER" : "cve@rapid7.com" ,
"DATE_PUBLIC" : "2022-06-30T21:07:00.000Z" ,
2022-06-30 19:00:46 +00:00
"ID" : "CVE-2022-34879" ,
2022-07-05 10:38:14 -05:00
"STATE" : "PUBLIC" ,
"TITLE" : "VICIDial 2.14b0.5 SVN 3550 was discovered to contain multiple Cross Site Scripting (XSS) vulnerabilities at /vicidial/admin.php."
2022-06-30 19:00:46 +00:00
} ,
2022-07-05 10:38:14 -05:00
"affects" : {
"vendor" : {
"vendor_data" : [
{
"product" : {
"product_data" : [
{
"product_name" : "VICIdial" ,
"version" : {
"version_data" : [
{
"version_affected" : "<" ,
"version_name" : "2.14b0.5" ,
"version_value" : "3555"
}
]
}
}
]
} ,
"vendor_name" : "VICIdial"
}
]
}
} ,
"credit" : [
{
"lang" : "eng" ,
"value" : "h00die for discovery, disclosure, and exploit. Matt Florell with VICIdial for patching the software."
}
] ,
"data_format" : "MITRE" ,
"data_type" : "CVE" ,
"data_version" : "4.0" ,
2022-06-30 19:00:46 +00:00
"description" : {
"description_data" : [
{
"lang" : "eng" ,
2022-07-05 16:00:44 +00:00
"value" : "Reflected Cross Site Scripting (XSS) vulnerabilities in AST Agent Time Sheet interface (/vicidial/AST_agent_time_sheet.php) of VICIdial via agent, and search_archived_data parameters. This issue affects: VICIdial 2.14b0.5 versions prior to 3555."
2022-07-05 10:38:14 -05:00
}
]
} ,
"generator" : {
"engine" : "Vulnogram 0.0.9"
} ,
"impact" : {
"cvss" : {
"attackComplexity" : "LOW" ,
"attackVector" : "NETWORK" ,
"availabilityImpact" : "LOW" ,
"baseScore" : 6.5 ,
"baseSeverity" : "MEDIUM" ,
"confidentialityImpact" : "LOW" ,
"integrityImpact" : "LOW" ,
"privilegesRequired" : "LOW" ,
"scope" : "CHANGED" ,
"userInteraction" : "REQUIRED" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" ,
"version" : "3.1"
}
} ,
"problemtype" : {
"problemtype_data" : [
{
"description" : [
{
"lang" : "eng" ,
"value" : "CWE-79 Cross-site Scripting (XSS)"
}
]
2022-06-30 19:00:46 +00:00
}
]
2022-07-05 10:38:14 -05:00
} ,
"references" : {
"reference_data" : [
{
"name" : "https://www.vicidial.org/VICIDIALforum/viewtopic.php?f=4&t=41300&sid=aacb27a29fefd85265b4d55fe51122af" ,
"refsource" : "CONFIRM" ,
"url" : "https://www.vicidial.org/VICIDIALforum/viewtopic.php?f=4&t=41300&sid=aacb27a29fefd85265b4d55fe51122af"
}
]
} ,
"solution" : [
{
"lang" : "eng" ,
"value" : "Upgrade to SVN release 3583 or later."
}
] ,
"source" : {
"discovery" : "EXTERNAL"
2022-06-30 19:00:46 +00:00
}
2022-07-05 16:00:44 +00:00
}