CVE-2022-42960

EqualWeb Accessibility Widget 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.1.10, 3.0.0, 3.0.1, 3.0.2, 4.0.0, and 4.0.1 allows DOM XSS due to improper validation of message events to accessibility.js.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.4 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
mitreCNA
---
---
CVEADP
---
---
CISA-ADPADP
5.4 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 38%
VendorProductVersion
equalwebequalweb_accessibility_widget
2.0.0
equalwebequalweb_accessibility_widget
2.0.1
equalwebequalweb_accessibility_widget
2.0.2
equalwebequalweb_accessibility_widget
2.0.3
equalwebequalweb_accessibility_widget
2.0.4
equalwebequalweb_accessibility_widget
2.1.10
equalwebequalweb_accessibility_widget
3.0.0
equalwebequalweb_accessibility_widget
3.0.1
equalwebequalweb_accessibility_widget
3.0.2
equalwebequalweb_accessibility_widget
4.0.0
equalwebequalweb_accessibility_widget
4.0.1
𝑥
= Vulnerable software versions