Vulnerability Details CVE-2022-22812
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause a web session compromise when an attacker injects and then executes arbitrary malicious JavaScript code inside the target browser. Affected Product: spaceLYnk (V2.6.2 and prior), Wiser for KNX (formerly homeLYnk) (V2.6.2 and prior), fellerLYnk (V2.6.2 and prior)
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 65.8%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 4.3
Products affected by CVE-2022-22812
-
cpe:2.3:h:schneider-electric:fellerlynk:-
-
cpe:2.3:h:schneider-electric:spacelynk:-
-
cpe:2.3:h:schneider-electric:wiser_for_knx:-
-
cpe:2.3:o:schneider-electric:fellerlynk_firmware:2.6.1
-
cpe:2.3:o:schneider-electric:fellerlynk_firmware:2.6.2
-
cpe:2.3:o:schneider-electric:spacelynk_firmware:-
-
cpe:2.3:o:schneider-electric:spacelynk_firmware:1.0.0
-
cpe:2.3:o:schneider-electric:spacelynk_firmware:1.1.0
-
cpe:2.3:o:schneider-electric:spacelynk_firmware:1.1.1
-
cpe:2.3:o:schneider-electric:spacelynk_firmware:1.2.1
-
cpe:2.3:o:schneider-electric:spacelynk_firmware:2.0.0
-
cpe:2.3:o:schneider-electric:spacelynk_firmware:2.0.1
-
cpe:2.3:o:schneider-electric:spacelynk_firmware:2.1.0
-
cpe:2.3:o:schneider-electric:spacelynk_firmware:2.1.1
-
cpe:2.3:o:schneider-electric:spacelynk_firmware:2.3.0
-
cpe:2.3:o:schneider-electric:spacelynk_firmware:2.4.0
-
cpe:2.3:o:schneider-electric:spacelynk_firmware:2.5.0
-
cpe:2.3:o:schneider-electric:spacelynk_firmware:2.5.1
-
cpe:2.3:o:schneider-electric:spacelynk_firmware:2.6.2
-
cpe:2.3:o:schneider-electric:wiser_for_knx_firmware:-
-
cpe:2.3:o:schneider-electric:wiser_for_knx_firmware:2.1.0
-
cpe:2.3:o:schneider-electric:wiser_for_knx_firmware:2.1.1
-
cpe:2.3:o:schneider-electric:wiser_for_knx_firmware:2.3.0
-
cpe:2.3:o:schneider-electric:wiser_for_knx_firmware:2.4.0
-
cpe:2.3:o:schneider-electric:wiser_for_knx_firmware:2.5.0
-
cpe:2.3:o:schneider-electric:wiser_for_knx_firmware:2.5.1
-
cpe:2.3:o:schneider-electric:wiser_for_knx_firmware:2.6.2