VDB
CVE-2022-20765
CVE-2022-20765
PUBLISHED
CVSS 4.800000190734863 MEDIUM
A vulnerability in the web applications of Cisco UCS Director could allow an authenticated, remote attacker to conduct a cross-site scripting attack on an affected system. This vulnerability is due to unsanitized user input. An attacker could exploit this vulnerability by submitting custom JavaScript to affected web applications. A successful exploit could allow the attacker to rewrite web page content, access sensitive information stored in the applications, and alter data by submitting forms.
EPSS 0.16% · 36.8th percentile
Risk Scores
CVSS 3.1
4.800000190734863
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
EPSS Score
0.16%
36.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Cisco UCS Director | n/a |
| cisco | ucs_director | 0 |
Exploit Intelligence
Timeline
- May 27, 2022 CVE Published
- May 28, 2022 EPSS Score
- Jul 17, 2022 EPSS Score
- Sep 3, 2022 EPSS Score
- Oct 22, 2022 EPSS Score
- Dec 10, 2022 EPSS Score
- Jan 27, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 17, 2023 EPSS Score
- May 5, 2023 EPSS Score
- Jun 23, 2023 EPSS Score
- Aug 10, 2023 EPSS Score