CVE-2022-37461
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD
Description
Multiple cross-site scripting (XSS) vulnerabilities in Canon Medical Vitrea View 7.x before 7.7.6 allow remote attackers to inject arbitrary web script or HTML via (1) the input after the error subdirectory to the /vitrea-view/error/ subdirectory, or the (2) groupID, (3) offset, or (4) limit parameter to an Administrative Panel (Group and Users) page. There is a risk of an attacker retrieving patient information.
Affected (1)
Products: Canon: Medical Vitrea View
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 7.0 to 7.7.6 |
References (6)
Source: cve@mitre.org
ExploitThird Party Advisory
https://www.vitalimages.com/customer-success-support-program/vital-images-software-security-updates/
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
https://www.vitalimages.com/customer-success-support-program/vital-images-software-security-updates/
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ProductVendor Advisory
Timeline
No history available yet.