Quanos "SCHEMA ST4" example web templates in version Bootstrap 2019 v2/2021 v1/2022 v1/2022 SP1 v1 or below are prone to JavaScript injection allowing a remote attacker to hijack existing sessions to e.g. other web services in the same environment or execute scripts in the users browser environment. The affected script is '*-schema.js'.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Weidmueller
Subscribe
|
19 Iot Md01 Lan H4 S0011
Subscribe
19 Iot Md01 Lan H4 S0011 Firmware
Subscribe
Fp Iot Md01 4eu S2 00000
Subscribe
Fp Iot Md01 4eu S2 00000 Firmware
Subscribe
Fp Iot Md01 Lan S2 00000
Subscribe
Fp Iot Md01 Lan S2 00000 Firmware
Subscribe
Fp Iot Md01 Lan S2 00011
Subscribe
Fp Iot Md01 Lan S2 00011 Firmware
Subscribe
Fp Iot Md02 4eu S3 00000
Subscribe
Fp Iot Md02 4eu S3 00000 Firmware
Subscribe
Iot-gw30
Subscribe
Iot-gw30-4g-eu
Subscribe
Iot-gw30-4g-eu Firmware
Subscribe
Iot-gw30 Firmware
Subscribe
Uc20-wl2000-ac
Subscribe
Uc20-wl2000-ac Firmware
Subscribe
Uc20-wl2000-iot
Subscribe
Uc20-wl2000-iot Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-42502 | Quanos "SCHEMA ST4" example web templates in version Bootstrap 2019 v2/2021 v1/2022 v1/2022 SP1 v1 or below are prone to JavaScript injection allowing a remote attacker to hijack existing sessions to e.g. other web services in the same environment or execute scripts in the users browser environment. The affected script is '*-schema.js'. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://cert.vde.com/de/advisories/VDE-2022-056/ |
|
History
Thu, 17 Apr 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2025-04-17T20:21:13.344Z
Reserved: 2022-09-01T06:57:09.197Z
Link: CVE-2022-3073
Updated: 2024-08-03T01:00:10.683Z
Status : Modified
Published: 2022-12-14T09:15:09.163
Modified: 2024-11-21T07:18:46.040
Link: CVE-2022-3073
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD