2024-12-08 03:06:42 +00:00

123 lines
4.0 KiB
JSON

{
"id": "CVE-2022-36783",
"sourceIdentifier": "cna@cyber.gov.il",
"published": "2022-10-25T17:15:55.210",
"lastModified": "2024-11-21T07:13:43.810",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "AlgoSec \u2013 FireFlow Reflected Cross-Site-Scripting (RXSS) A malicious user injects JavaScript code into a parameter called IntersectudRule on the search/result.html page. The malicious user changes the request from POST to GET and sends the URL to another user (victim). JavaScript code is executed on the browser of the other user."
},
{
"lang": "es",
"value": "AlgoSec - FireFlow Reflected Cross-Site-Scripting (RXSS) Un usuario malicioso inyecta c\u00f3digo JavaScript en un par\u00e1metro llamado IntersectudRule en la p\u00e1gina search/result.html. El usuario malicioso cambia la petici\u00f3n de POST a GET y env\u00eda la URL a otro usuario (v\u00edctima). El c\u00f3digo JavaScript se ejecuta en el navegador del otro usuario"
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "cna@cyber.gov.il",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"attackVector": "ADJACENT_NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "CHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"availabilityImpact": "LOW"
},
"exploitabilityScore": 2.3,
"impactScore": 3.7
},
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "REQUIRED",
"scope": "CHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 2.3,
"impactScore": 2.7
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:algosec:fireflow:*:*:*:*:*:*:*:*",
"versionStartIncluding": "a32.0",
"versionEndExcluding": "a32.0.580-277",
"matchCriteriaId": "7B34C315-2667-4A01-9DEF-DE6290D35134"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:algosec:fireflow:*:*:*:*:*:*:*:*",
"versionStartIncluding": "a32.10",
"versionEndExcluding": "a32.10.410-212",
"matchCriteriaId": "921BD92C-2284-435D-8228-037FE0ADFAB6"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:algosec:fireflow:*:*:*:*:*:*:*:*",
"versionStartIncluding": "a32.20",
"versionEndExcluding": "a32.20.230-35",
"matchCriteriaId": "DE55D7A3-C609-4EC5-A657-4D9F96087CA8"
}
]
}
]
}
],
"references": [
{
"url": "https://www.gov.il/en/Departments/faq/cve_advisories",
"source": "cna@cyber.gov.il",
"tags": [
"Third Party Advisory"
]
},
{
"url": "https://www.gov.il/en/Departments/faq/cve_advisories",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Third Party Advisory"
]
}
]
}