// For flags

CVE-2022-3073

Quaonos Schema ST4 example templates prone to XSS

Severity Score

6.1
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Track
*SSVC
Descriptions

Quanos "SCHEMA ST4" example web templates in version Bootstrap 2019 v2/2021 v1/2022 v1/2022 SP1 v1 or below are prone to JavaScript injection allowing a remote attacker to hijack existing sessions to e.g. other web services in the same environment or execute scripts in the users browser environment. The affected script is '*-schema.js'.

Las plantillas web de ejemplo "SCHEMA ST4" de Quanos en la versión Bootstrap 2019 v2/2021 v1/2022 v1/2022 SP1 v1 o inferior son propensas a la inyección de JavaScript, lo que permite a un atacante remoto secuestrar sesiones existentes para, por ejemplo, otros servicios web en el mismo entorno o ejecutar scripts. en el entorno del navegador de los usuarios. El script afectado es '*-schema.js'.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:Track
Exploitation
None
Automatable
No
Tech. Impact
Partial
* Organization's Worst-case Scenario
Timeline
  • 2022-09-01 CVE Reserved
  • 2022-12-14 CVE Published
  • 2025-03-30 EPSS Updated
  • 2025-04-17 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
  • CAPEC-63: Cross-Site Scripting (XSS)
References (1)
URL Tag Source
https://cert.vde.com/de/advisories/VDE-2022-056 Third Party Advisory
URL Date SRC
URL Date SRC
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Weidmueller
Search vendor "Weidmueller"
19 Iot Md01 Lan H4 S0011 Firmware
Search vendor "Weidmueller" for product "19 Iot Md01 Lan H4 S0011 Firmware"
--
Affected
in Weidmueller
Search vendor "Weidmueller"
19 Iot Md01 Lan H4 S0011
Search vendor "Weidmueller" for product "19 Iot Md01 Lan H4 S0011"
--
Safe
Weidmueller
Search vendor "Weidmueller"
Fp Iot Md01 4eu S2 00000 Firmware
Search vendor "Weidmueller" for product "Fp Iot Md01 4eu S2 00000 Firmware"
--
Affected
in Weidmueller
Search vendor "Weidmueller"
Fp Iot Md01 4eu S2 00000
Search vendor "Weidmueller" for product "Fp Iot Md01 4eu S2 00000"
--
Safe
Weidmueller
Search vendor "Weidmueller"
Fp Iot Md01 Lan S2 00000 Firmware
Search vendor "Weidmueller" for product "Fp Iot Md01 Lan S2 00000 Firmware"
--
Affected
in Weidmueller
Search vendor "Weidmueller"
Fp Iot Md01 Lan S2 00000
Search vendor "Weidmueller" for product "Fp Iot Md01 Lan S2 00000"
--
Safe
Weidmueller
Search vendor "Weidmueller"
Fp Iot Md01 Lan S2 00011 Firmware
Search vendor "Weidmueller" for product "Fp Iot Md01 Lan S2 00011 Firmware"
--
Affected
in Weidmueller
Search vendor "Weidmueller"
Fp Iot Md01 Lan S2 00011
Search vendor "Weidmueller" for product "Fp Iot Md01 Lan S2 00011"
--
Safe
Weidmueller
Search vendor "Weidmueller"
Fp Iot Md02 4eu S3 00000 Firmware
Search vendor "Weidmueller" for product "Fp Iot Md02 4eu S3 00000 Firmware"
--
Affected
in Weidmueller
Search vendor "Weidmueller"
Fp Iot Md02 4eu S3 00000
Search vendor "Weidmueller" for product "Fp Iot Md02 4eu S3 00000"
--
Safe
Weidmueller
Search vendor "Weidmueller"
Iot-gw30 Firmware
Search vendor "Weidmueller" for product "Iot-gw30 Firmware"
<= 1.16.0
Search vendor "Weidmueller" for product "Iot-gw30 Firmware" and version " <= 1.16.0"
-
Affected
in Weidmueller
Search vendor "Weidmueller"
Iot-gw30
Search vendor "Weidmueller" for product "Iot-gw30"
--
Safe
Weidmueller
Search vendor "Weidmueller"
Iot-gw30-4g-eu Firmware
Search vendor "Weidmueller" for product "Iot-gw30-4g-eu Firmware"
<= 1.16.0
Search vendor "Weidmueller" for product "Iot-gw30-4g-eu Firmware" and version " <= 1.16.0"
-
Affected
in Weidmueller
Search vendor "Weidmueller"
Iot-gw30-4g-eu
Search vendor "Weidmueller" for product "Iot-gw30-4g-eu"
--
Safe
Weidmueller
Search vendor "Weidmueller"
Uc20-wl2000-ac Firmware
Search vendor "Weidmueller" for product "Uc20-wl2000-ac Firmware"
<= 1.16.0
Search vendor "Weidmueller" for product "Uc20-wl2000-ac Firmware" and version " <= 1.16.0"
-
Affected
in Weidmueller
Search vendor "Weidmueller"
Uc20-wl2000-ac
Search vendor "Weidmueller" for product "Uc20-wl2000-ac"
--
Safe
Weidmueller
Search vendor "Weidmueller"
Uc20-wl2000-iot Firmware
Search vendor "Weidmueller" for product "Uc20-wl2000-iot Firmware"
<= 1.16.0
Search vendor "Weidmueller" for product "Uc20-wl2000-iot Firmware" and version " <= 1.16.0"
-
Affected
in Weidmueller
Search vendor "Weidmueller"
Uc20-wl2000-iot
Search vendor "Weidmueller" for product "Uc20-wl2000-iot"
--
Safe