CVE-2022-37317
Last modified
CVE-2022-37317 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. Archer Platform 6.x before 6.11 P3 contain an HTML injection vulnerability. An authenticated remote attacker could potentially exploit this vulnerability by tricking a victim application user to execute malicious code in the context of the web application. EPSS estimates a 0.58% chance of exploitation in the next 30 days.
Description
Archer Platform 6.x before 6.11 P3 contain an HTML injection vulnerability. An authenticated remote attacker could potentially exploit this vulnerability by tricking a victim application user to execute malicious code in the context of the web application. 6.10 P4 (6.10.0.4) and 6.11 P2 HF4 (6.11.0.2.4) are also fixed releases.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Rsa | Archer | >= 6.0, < 6.10.0.4 |
| Rsa | Archer | >= 6.11, < 6.11.0.2.4 |
References
- https://archerirm.comProduct
- https://archerirm.comProduct
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-37317?
How severe is CVE-2022-37317?
How do I fix CVE-2022-37317?
Are you affected by CVE-2022-37317?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
