ZeroHour

CVE-2022-25172

PoC
CVSS 3.1
6.1 medium
EPSS
1%p61
Published
()
Modified
Description

An information disclosure vulnerability exists in the web interface session cookie functionality of InHand Networks InRouter302 V3.5.4. The session cookie misses the HttpOnly flag, making it accessible via JavaScript and thus allowing an attacker, able to perform an XSS attack, to steal the session cookie.

Vendors
inhandnetworks
Products
ir302 firmware
Weakness
CWE-1004, CWE-732
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.