CVE-2022-37318
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Archer Platform 6.9 SP2 P2 before 6.11 P3 (6.11.0.3) contain a reflected XSS vulnerability. A remote unauthenticated malicious Archer user could potentially exploit this vulnerability by tricking a victim application user into supplying malicious JavaScript code to the vulnerable web application. This code is then reflected to the victim and gets executed by the web browser in the context of the vulnerable web application. 6.10 P4 (6.10.0.4) and 6.11 P2 HF4 (6.11.0.2.4) are also fixed releases.
Archer Platform versiones 6.9 SP2 P2 anteriores a 6.11 P3 (6.11.0.3) contiene una vulnerabilidad de tipo XSS reflejado. Un usuario remoto no autenticado de Archer podría explotar esta vulnerabilidad al engañar a un usuario de la aplicación víctima para que suministre código JavaScript malicioso a la aplicación web vulnerable. Este código es reflejado en la víctima y es ejecutado por el navegador web en el contexto de la aplicación web vulnerable. Las versiones 6.10 P4 (6.10.0.4) y 6.11 P2 HF4 (6.11.0.2.4) también son versiones corregidas.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-08-01 CVE Reserved
- 2022-08-25 CVE Published
- 2024-08-03 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (2)
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Rsa Search vendor "Rsa" | Archer Search vendor "Rsa" for product "Archer" | >= 6.9.2.2 < 6.10.0.4 Search vendor "Rsa" for product "Archer" and version " >= 6.9.2.2 < 6.10.0.4" | - |
Affected
| ||||||
Rsa Search vendor "Rsa" | Archer Search vendor "Rsa" for product "Archer" | >= 6.11 < 6.11.0.2.4 Search vendor "Rsa" for product "Archer" and version " >= 6.11 < 6.11.0.2.4" | - |
Affected
|