// For flags

CVE-2022-24573

 

Severity Score

6.1
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A stored cross-site scripting (XSS) vulnerability in the admin interface in Element-IT HTTP Commander 7.0.0 allows unauthenticated users to get admin access by injecting a malicious script in the User-Agent field.

Una vulnerabilidad de tipo cross-site scripting (XSS) almacenada en la interfaz de administraciĆ³n en Element-IT HTTP Commander versiĆ³n 7.0.0, permite a usuarios no autenticados conseguir acceso de administrador inyectando un script malicioso en el campo User-Agent

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-02-07 CVE Reserved
  • 2022-03-03 CVE Published
  • 2024-08-03 CVE Updated
  • 2024-11-16 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (2)
URL Tag Source
URL Date SRC
URL Date SRC
URL Date SRC
http://element-it.com 2022-03-09
https://www.element-it.com/news.aspx 2022-03-09
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Element-it
Search vendor "Element-it"
Http Commander
Search vendor "Element-it" for product "Http Commander"
>= 5.0.0 < 5.3.6
Search vendor "Element-it" for product "Http Commander" and version " >= 5.0.0 < 5.3.6"
-
Affected
Element-it
Search vendor "Element-it"
Http Commander
Search vendor "Element-it" for product "Http Commander"
7.0.0
Search vendor "Element-it" for product "Http Commander" and version "7.0.0"
-
Affected