« Volver al listado

CVE-2022-40257

Estado: ModificadaMedia (5.4)—

An HTML injection vulnerability exists in CERT/CC VINCE software prior to 1.50.4. An authenticated attacker can inject arbitrary HTML via a crafted email with HTML content in the Subject field.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-40257",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 5.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.3
      }
    ]
  },
  "affected": [
    {
      "source": "cret@cert.org",
      "affectedData": [
        {
          "vendor": "CERT/CC",
          "product": "VINCE - The Vulnerability Information and Coordination Environment",
          "versions": [
            {
              "status": "affected",
              "version": "1.48.0",
              "lessThan": "1.50.4",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-10-10T20:15:09.793",
  "references": [
    {
      "url": "https://github.com/CERTCC/VINCE/issues?q=label%3Asecurity",
      "tags": [
        "Issue Tracking",
        "Third Party Advisory"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "https://github.com/CERTCC/VINCE/issues?q=label%3Asecurity",
      "tags": [
        "Issue Tracking",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cret@cert.org",
      "description": [
        {
          "lang": "en",
          "value": "CWE-74"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An HTML injection vulnerability exists in CERT/CC VINCE software prior to 1.50.4. An authenticated attacker can inject arbitrary HTML via a crafted email with HTML content in the Subject field."
    },
    {
      "lang": "es",
      "value": "Se presenta una vulnerabilidad de inyección HTML en el software CERT/CC VINCE versiones anteriores a 1.50.4. Un atacante autenticado puede inyectar HTML arbitrario por medio de un correo electrónico diseñado con contenido HTML en el campo Subject"
    }
  ],
  "lastModified": "2026-06-17T05:01:10.940",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:cert:vince:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "841576D6-9C93-404A-8249-AD59C0B276DD",
              "versionEndExcluding": "1.50.4"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cret@cert.org"
}