CVE-2022-40248
An HTML injection vulnerability exists in CERT/CC VINCE software prior to version 1.50.4
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
An HTML injection vulnerability exists in CERT/CC VINCE software prior to 1.50.4. An authenticated attacker can inject arbitrary HTML via form using the "Product Affected" field.
| CWE | CWE-74 |
| Vendor | cert/cc |
| Product | vince - the vulnerability information and coordination environment |
| Published | Oct 10, 2022 |
| Last Updated | Aug 3, 2024 |
Stay Ahead of the Next One
Get instant alerts for cert/cc vince - the vulnerability information and coordination environment
Be the first to know when new unknown vulnerabilities affecting cert/cc vince - the vulnerability information and coordination environment are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
CERT/CC / VINCE - The Vulnerability Information and Coordination Environment
1.48.0 < 1.50.4
References
Credits
Rapid7 researcher Nick Sanzotta discovered and reported this security vulnerability to CERT/CC