Security Advisory

CVE-2022-39301

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2022-10-19 00:00:00
Last updated 2025-04-22 17:18:21
Assigner GitHub_M
CVSS score 8.2
State PUBLISHED

Description

sra-admin is a background rights management system that separates the front and back end. sra-admin version 1.1.1 has a storage cross-site scripting (XSS) vulnerability. After logging into the sra-admin background, an attacker can upload an html page containing xss attack code in "Personal Center" - "Profile Picture Upload" allowing theft of the user's personal information. This issue has been patched in 1.1.2. There are no known workarounds.