CVE-2022-36859
https://notcve.org/view.php?id=CVE-2022-36859
Improper input validation vulnerability in SmartTagPlugin prior to version 1.2.21-6 allows privileged attackers to trigger a XSS on a victim's devices. Una vulnerabilidad de comprobación de entrada inapropiada en SmartTagPlugin versiones anteriores a 1.2.21-6, permite a atacantes privilegiados desencadenar un ataque de tipo XSS en los dispositivos de la víctima • https://security.samsungmobile.com/serviceWeb.smsb?year=2022&month=09 • CWE-20: Improper Input Validation CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2022-24926
https://notcve.org/view.php?id=CVE-2022-24926
Improper input validation vulnerability in SmartTagPlugin prior to version 1.2.15-6 allows privileged attackers to trigger a XSS on a victim's devices. Una vulnerabilidad de comprobación de entrada inapropiada en SmartTagPlugin versiones anteriores a 1.2.15-6, permite a atacantes con privilegios desencadenar un ataque de tipo XSS en los dispositivos de la víctima • https://security.samsungmobile.com/serviceWeb.smsb?year=2022&month=2 • CWE-20: Improper Input Validation CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •