ZeroHour

CVE-2022-48020

PoC
CVSS 3.1
6.1 medium
EPSS
<1%p47
Published
()
Modified
Description

Vinteo VCC v2.36.4 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the conference parameter. This vulnerability allows attackers to inject arbitrary code which will be executed by the victim user's browser.

Vendors
vinteo
Products
video core
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.