CVE-2022-4559

A vulnerability was found in INEX IPX-Manager up to 6.2.0. It has been declared as problematic. This vulnerability affects unknown code of the file resources/views/customer/list.foil.php. The manipulation leads to cross site scripting. The attack can be initiated remotely. Upgrading to version 6.3.0 is able to address this issue. The name of the patch is bc9b14c6f70cccdb89b559e8bc3a7318bfe9c243. It is recommended to upgrade the affected component. VDB-215962 is the identifier assigned to this vulnerability.
References
Link Resource
https://github.com/inex/IXP-Manager/commit/bc9b14c6f70cccdb89b559e8bc3a7318bfe9c243 Patch Third Party Advisory
https://vuldb.com/?id.215962 Permissions Required Third Party Advisory
https://github.com/inex/IXP-Manager/releases/tag/v6.3.0 Release Notes Third Party Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:inex:ixp_manager:*:*:*:*:*:*:*:*

Information

Published : 2022-12-16 09:15

Updated : 2022-12-21 10:24


NVD link : CVE-2022-4559

Mitre link : CVE-2022-4559


JSON object : View

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-707

Improper Neutralization

CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Advertisement

dedicated server usa

Products Affected

inex

  • ixp_manager