CVE-2022-3073
Quanos "SCHEMA ST4" example web templates in version Bootstrap 2019 v2/2021 v1/2022 v1/2022 SP1 v1 or below are prone to JavaScript injection allowing a remote attacker to hijack existing sessions to e.g. other web services in the same environment or execute scripts in the users browser environment. The affected script is '*-schema.js'.
Published:Dec 14, 2022
Last Modified:Apr 17, 2025
EPS:Dec 14, 2022
EPSS Score:0.00118
CVSS Score:6.1
Affected Products
Vendor
Product
Action
Vendor
Weidmueller
Product
19 Iot Md01 Lan H4 S0011
Weidmueller
19 Iot Md01 Lan H4 S0011
Vendor
Weidmueller
Product
19 Iot Md01 Lan H4 S0011 Firmware
Weidmueller
19 Iot Md01 Lan H4 S0011 Firmware
Vendor
Weidmueller
Product
Fp Iot Md01 4eu S2 00000
Weidmueller
Fp Iot Md01 4eu S2 00000
Vendor
Weidmueller
Product
Fp Iot Md01 4eu S2 00000 Firmware
Weidmueller
Fp Iot Md01 4eu S2 00000 Firmware
Vendor
Weidmueller
Product
Fp Iot Md01 Lan S2 00000
Weidmueller
Fp Iot Md01 Lan S2 00000
Vendor
Weidmueller
Product
Fp Iot Md01 Lan S2 00000 Firmware
Weidmueller
Fp Iot Md01 Lan S2 00000 Firmware
Vendor
Weidmueller
Product
Fp Iot Md01 Lan S2 00011
Weidmueller
Fp Iot Md01 Lan S2 00011
Vendor
Weidmueller
Product
Fp Iot Md01 Lan S2 00011 Firmware
Weidmueller
Fp Iot Md01 Lan S2 00011 Firmware
Vendor
Weidmueller
Product
Fp Iot Md02 4eu S3 00000
Weidmueller
Fp Iot Md02 4eu S3 00000
Vendor
Weidmueller
Product
Fp Iot Md02 4eu S3 00000 Firmware
Weidmueller
Fp Iot Md02 4eu S3 00000 Firmware
Vendor
Weidmueller
Product
Iot-gw30
Weidmueller
Iot-gw30
Vendor
Weidmueller
Product
Iot-gw30-4g-eu
Weidmueller
Iot-gw30-4g-eu
Vendor
Weidmueller
Product
Iot-gw30-4g-eu Firmware
Weidmueller
Iot-gw30-4g-eu Firmware
Vendor
Weidmueller
Product
Iot-gw30 Firmware
Weidmueller
Iot-gw30 Firmware
Vendor
Weidmueller
Product
Uc20-wl2000-ac
Weidmueller
Uc20-wl2000-ac
Vendor
Weidmueller
Product
Uc20-wl2000-ac Firmware
Weidmueller
Uc20-wl2000-ac Firmware
Vendor
Weidmueller
Product
Uc20-wl2000-iot
Weidmueller
Uc20-wl2000-iot
Vendor
Weidmueller
Product
Uc20-wl2000-iot Firmware
Weidmueller
Uc20-wl2000-iot Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
