Quanos "SCHEMA ST4" example web templates in version Bootstrap 2019 v2/2021 v1/2022 v1/2022 SP1 v1 or below are prone to JavaScript injection allowing a remote attacker to hijack existing sessions to e.g. other web services in the same environment or execute scripts in the users browser environment. The affected script is '*-schema.js'.

Project Subscriptions

Vendors Products
Weidmueller Subscribe
19 Iot Md01 Lan H4 S0011 Subscribe
19 Iot Md01 Lan H4 S0011 Firmware Subscribe
Fp Iot Md01 4eu S2 00000 Subscribe
Fp Iot Md01 4eu S2 00000 Firmware Subscribe
Fp Iot Md01 Lan S2 00000 Subscribe
Fp Iot Md01 Lan S2 00000 Firmware Subscribe
Fp Iot Md01 Lan S2 00011 Subscribe
Fp Iot Md01 Lan S2 00011 Firmware Subscribe
Fp Iot Md02 4eu S3 00000 Subscribe
Fp Iot Md02 4eu S3 00000 Firmware Subscribe
Iot-gw30 Subscribe
Iot-gw30-4g-eu Subscribe
Iot-gw30-4g-eu Firmware Subscribe
Iot-gw30 Firmware Subscribe
Uc20-wl2000-ac Subscribe
Uc20-wl2000-ac Firmware Subscribe
Uc20-wl2000-iot Subscribe
Uc20-wl2000-iot Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2022-42502 Quanos "SCHEMA ST4" example web templates in version Bootstrap 2019 v2/2021 v1/2022 v1/2022 SP1 v1 or below are prone to JavaScript injection allowing a remote attacker to hijack existing sessions to e.g. other web services in the same environment or execute scripts in the users browser environment. The affected script is '*-schema.js'.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 17 Apr 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2025-04-17T20:21:13.344Z

Reserved: 2022-09-01T06:57:09.197Z

Link: CVE-2022-3073

cve-icon Vulnrichment

Updated: 2024-08-03T01:00:10.683Z

cve-icon NVD

Status : Modified

Published: 2022-12-14T09:15:09.163

Modified: 2024-11-21T07:18:46.040

Link: CVE-2022-3073

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses