« Volver al listado

CVE-2022-40248

Estado: ModificadaMedia (5.4)—

An HTML injection vulnerability exists in CERT/CC VINCE software prior to 1.50.4. An authenticated attacker can inject arbitrary HTML via form using the "Product Affected" field.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-40248",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 5.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.3
      }
    ]
  },
  "affected": [
    {
      "source": "cret@cert.org",
      "affectedData": [
        {
          "vendor": "CERT/CC",
          "product": "VINCE - The Vulnerability Information and Coordination Environment",
          "versions": [
            {
              "status": "affected",
              "version": "1.48.0",
              "lessThan": "1.50.4",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-10-10T20:15:09.727",
  "references": [
    {
      "url": "https://github.com/CERTCC/VINCE/issues?q=label%3Asecurity",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "https://github.com/CERTCC/VINCE/issues?q=label%3Asecurity",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cret@cert.org",
      "description": [
        {
          "lang": "en",
          "value": "CWE-74"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An HTML injection vulnerability exists in CERT/CC VINCE software prior to 1.50.4. An authenticated attacker can inject arbitrary HTML via form using the \"Product Affected\" field."
    },
    {
      "lang": "es",
      "value": "El software CERT/CC VINCE versiones anteriores a 1.50.4 presenta una vulnerabilidad de inyección de HTML. Un atacante autenticado puede inyectar HTML arbitrario por medio de un formulario usando el campo \"Product Affected\""
    }
  ],
  "lastModified": "2026-06-17T05:01:10.663",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:cert:vince:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "841576D6-9C93-404A-8249-AD59C0B276DD",
              "versionEndExcluding": "1.50.4"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cret@cert.org"
}