CVE-2022-37318
Last modified
CVE-2022-37318 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. Archer Platform 6.9 SP2 P2 before 6.11 P3 (6.11.0.3) contain a reflected XSS vulnerability. A remote unauthenticated malicious Archer user could potentially exploit this vulnerability by tricking a victim application user into supplying malicious JavaScript code to the vulnerable web application. EPSS estimates a 0.43% chance of exploitation in the next 30 days.
Description
Archer Platform 6.9 SP2 P2 before 6.11 P3 (6.11.0.3) contain a reflected XSS vulnerability. A remote unauthenticated malicious Archer user could potentially exploit this vulnerability by tricking a victim application user into supplying malicious JavaScript code to the vulnerable web application. This code is then reflected to the victim and gets executed by the web browser in the context of the vulnerable web application. 6.10 P4 (6.10.0.4) and 6.11 P2 HF4 (6.11.0.2.4) are also fixed releases.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Rsa | Archer | >= 6.9.2.2, < 6.10.0.4 |
| Rsa | Archer | >= 6.11, < 6.11.0.2.4 |
References
- https://archerirm.comProduct
- https://archerirm.comProduct
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-37318?
How severe is CVE-2022-37318?
How do I fix CVE-2022-37318?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-37311OX App Suite through 7.10.6 has Uncontrolled Resource Consum…5.3
- CVE-2022-37312OX App Suite through 7.10.6 has Uncontrolled Resource Consum…5.3
- CVE-2022-37313OX App Suite through 7.10.6 allows SSRF because the anti-SSR…5.3
- CVE-2022-37315graphql-go (aka GraphQL for Go) through 0.8.0 has infinite r…7.5
- CVE-2022-37316Archer Platform 6.8 before 6.11 P3 (6.11.0.3) contains an im…6.5
- CVE-2022-37317Archer Platform 6.x before 6.11 P3 contain an HTML injection…5.4
- CVE-2022-3732A vulnerability was found in seccome Ehoney and classified a…9.8
- CVE-2022-37325In Sangoma Asterisk through 16.28.0, 17.x and 18.x through 1…7.5
- CVE-2022-37326Docker Desktop for Windows before 4.6.0 allows attackers to …7.8
- CVE-2022-37327Improper input validation in BIOS firmware for Intel(R) NUC,…5.5
- CVE-2022-37328Authenticated (author+) Stored Cross-Site Scripting (XSS) vu…5.4
- CVE-2022-37329Uncontrolled search path in some Intel(R) Quartus(R) Prime P…7.3
Are you affected by CVE-2022-37318?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
