CVE-2022-50787
5.3
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow more
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: disclosure@vulncheck.com (Secondary)
Description
SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x contains an unauthenticated stored cross-site scripting vulnerability in the username parameter that allows attackers to inject malicious scripts. Attackers can exploit the unvalidated username input to execute arbitrary HTML and JavaScript code in victim browser sessions without authentication.
Affected (12)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.15 |
| Running on/with | Platform Versions |
|---|---|
Sound4 First | Version 2.0 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.69 |
| Running on/with | Platform Versions |
|---|---|
Sound4 First | Version 1.0 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.16 |
| Running on/with | Platform Versions |
|---|---|
Sound4 Impact Eco | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.16 |
| Running on/with | Platform Versions |
|---|---|
Sound4 Pulse Eco | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.2 |
| Running on/with | Platform Versions |
|---|---|
Sound4 Big Voice4 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.30 |
| Running on/with | Platform Versions |
|---|---|
Sound4 Big Voice2 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.11 |
| Running on/with | Platform Versions |
|---|---|
Sound4 Wm2 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.4.29 |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.69 |
| Running on/with | Platform Versions |
|---|---|
Sound4 Pulse | Version 1.0 |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.15 |
| Running on/with | Platform Versions |
|---|---|
Sound4 Pulse | Version 2.0 |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.69 |
| Running on/with | Platform Versions |
|---|---|
Sound4 Impact | Version 1.0 |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.15 |
| Running on/with | Platform Versions |
|---|---|
Sound4 Impact | Version 2.0 |
References (5)
Source: disclosure@vulncheck.com
Third Party Advisory
Source: disclosure@vulncheck.com
ExploitThird Party AdvisoryVDB Entry
Source: disclosure@vulncheck.com
Third Party Advisory
Source: disclosure@vulncheck.com
ExploitThird Party Advisory
Timeline
No history available yet.