VYPR
Unrated severityNVD Advisory· Published Mar 9, 2022· Updated Apr 16, 2025

ICSA-22-062-01 IPCOMM ipDIO

CVE-2022-21146

Description

Persistent cross-site scripting in the web interface of ipDIO allows an unauthenticated remote attacker to introduce arbitrary JavaScript by injecting an XSS payload into a specific parameter. The XSS payload will be executed when a legitimate user attempts to review history.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.