Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-37461

Опубликовано: 30 сент. 2022
Источник: nvd
CVSS3: 6.1
EPSS Низкий

Описание

Multiple cross-site scripting (XSS) vulnerabilities in Canon Medical Vitrea View 7.x before 7.7.6 allow remote attackers to inject arbitrary web script or HTML via (1) the input after the error subdirectory to the /vitrea-view/error/ subdirectory, or the (2) groupID, (3) offset, or (4) limit parameter to an Administrative Panel (Group and Users) page. There is a risk of an attacker retrieving patient information.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:canon:medical_vitrea_view:*:*:*:*:*:*:*:*
Версия от 7.0 (включая) до 7.7.6 (исключая)

EPSS

Процентиль: 71%
0.00668
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79
CWE-79

Связанные уязвимости

CVSS3: 6.1
github
больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Canon Medical Vitrea View 7.x before 7.7.6 allow remote attackers to inject arbitrary web script or HTML via (1) the input after the error subdirectory to the /vitrea-view/error/ subdirectory, or the (2) groupID, (3) offset, or (4) limit parameter to an Administrative Panel (Group and Users) page. There is a risk of an attacker retrieving patient information.

EPSS

Процентиль: 71%
0.00668
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79
CWE-79