CVE-2022-42960

EUVD-2022-46015
EqualWeb Accessibility Widget 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.1.10, 3.0.0, 3.0.1, 3.0.2, 4.0.0, and 4.0.1 allows DOM XSS due to improper validation of message events to accessibility.js.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.4 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
CISA-ADPADP
5.4 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 56%
Affected Products (NVD)
VendorProductVersion
equalwebequalweb_accessibility_widget
2.0.0
equalwebequalweb_accessibility_widget
2.0.1
equalwebequalweb_accessibility_widget
2.0.2
equalwebequalweb_accessibility_widget
2.0.3
equalwebequalweb_accessibility_widget
2.0.4
equalwebequalweb_accessibility_widget
2.1.10
equalwebequalweb_accessibility_widget
3.0.0
equalwebequalweb_accessibility_widget
3.0.1
equalwebequalweb_accessibility_widget
3.0.2
equalwebequalweb_accessibility_widget
4.0.0
equalwebequalweb_accessibility_widget
4.0.1
𝑥
= Vulnerable software versions