CVE-2022-40190
CVE-2022-40190
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.8EPSS 0.7%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
31 Oct 2022Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
SAUTER Controls moduWeb firmware version 2.7.1 is vulnerable to reflective cross-site scripting (XSS). The web application does not adequately sanitize request strings of malicious JavaScript. An attacker utilizing XSS could then execute malicious code in users’ browsers and steal sensitive information, including user credentials.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
SAUTER Controls · moduWebWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →