CVE-2022-50787
SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x contains an unauthenticated stored cross-site scripting vulnerability in the username parameter that allows attackers to inject malicious scripts. Attackers can exploit the unvalidated username input to execute arbitrary HTML and JavaScript code in victim browser sessions without authentication.
Vendor
Product
CWE
Yayın Tarihi
2025-12-30 23:15:45
Güncelleme
2026-01-13 15:12:24
Source Identifier
disclosure@vulncheck.com
KEV Date Added
-
Kategoriler
Referanslar
https://exchange.xforce.ibmcloud.com/vulnerabilities/247920
https://packetstormsecurity.com/files/170258/SOUND4-IMPACT-FIRST-PULSE-Eco-2.x-Persistent-Cross-Site-Scripting.html
https://www.sound4.com/
https://www.vulncheck.com/advisories/sound-impactfirstpulseeco-x-unauthenticated-stored-cross-site-scripting
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5731.php