CVE-2022-37406
https://notcve.org/view.php?id=CVE-2022-37406
Cross-site scripting vulnerability in Aficio SP 4210N firmware versions prior to Web Support 1.05 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script. Vulnerabilidad de Cross-Site Scripting en versiones de firmware de Aficio SP 4210N anteriores a Web Support 1.05 permite a un atacante remoto autenticado con privilegios administrativos inyectar un script arbitrario. • https://jvn.jp/en/jp/JVN24659622/index.html https://support.ricoh.com/bb/html/dr_ut_e/rc3/model/sp42/sp42.htm https://support.ricoh.com/bbv2/html/dr_ut_d/ipsio/history/w/bb/pub_j/dr_ut_d/4101044/4101044791/V101/5236968/redirect_CLUTool_DOM/history.htm • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •