An issue was discovered in Comcast Defined Technologies microeisbss through 2021. An attacker can inject a stored XSS payload in the Device ID field under Inventory Management to achieve Remote Code Execution and privilege escalation..
References
Link | Resource |
---|---|
https://my.xfinity.com/vulnerabilityreport | Not Applicable |
https://pensecure.medium.com/cve-2022-45938-f4c0d441da6f | Exploit Press/Media Coverage |
Configurations
History
No history.
Information
Published : 2023-06-02 04:15
Updated : 2023-06-09 18:51
NVD link : CVE-2022-45938
Mitre link : CVE-2022-45938
CVE.ORG link : CVE-2022-45938
JSON object : View
Products Affected
xfinity
- comcast_defined_technologies_microeisbss
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')