CVE-2022-23397
04.03.2022, 15:15
The Cedar Gate EZ-NET portal 6.5.5 6.8.0 Internet portal has a call to display messages to users which does not properly sanitize data sent in through a URL parameter. This leads to a Reflected Cross-Site Scripting vulnerability. NOTE: the vendor disputes this because the ado.im reference has "no clear steps of reproduction."
Vendor | Product | Version |
---|---|---|
cedargate | ez-net_portal | 6.5.5 |
cedargate | ez-net_portal | 6.6.3 |
cedargate | ez-net_portal | 6.7.0 |
cedargate | ez-net_portal | 6.8.0 |
𝑥
= Vulnerable software versions