CVE-2022-28816
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD (Secondary)
Description
In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 the Sentilo Proxy is prone to reflected XSS which only affects the Sentilo service.
Affected (4)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.8.3 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 8.5.0.3 |
| Running on/with | Platform Versions |
|---|---|
Gavazziautomation Uwp 3.0 Monitoring Gateway And Controller | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 8.5.0.3 |
| Running on/with | Platform Versions |
|---|---|
Gavazziautomation Uwp 3.0 Monitoring Gateway And Controller | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 8.5.0.3 |
| Running on/with | Platform Versions |
|---|---|
Gavazziautomation Uwp 3.0 Monitoring Gateway And Controller | All versions |
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.