VYPR
Medium severity6.1NVD Advisory· Published Mar 4, 2022· Updated Jun 17, 2026

CVE-2022-23397

CVE-2022-23397

Description

The Cedar Gate EZ-NET portal 6.5.5 6.8.0 Internet portal has a call to display messages to users which does not properly sanitize data sent in through a URL parameter. This leads to a Reflected Cross-Site Scripting vulnerability. NOTE: the vendor disputes this because the ado.im reference has "no clear steps of reproduction."

Affected products

6
  • cpe:2.3:a:cedargate:ez-net_portal:6.5.5:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:cedargate:ez-net_portal:6.5.5:*:*:*:*:*:*:*
    • cpe:2.3:a:cedargate:ez-net_portal:6.6.3:*:*:*:*:*:*:*
    • cpe:2.3:a:cedargate:ez-net_portal:6.7.0:*:*:*:*:*:*:*
    • cpe:2.3:a:cedargate:ez-net_portal:6.8.0:*:*:*:*:*:*:*
    • (no CPE)range: 6.5.5, 6.8.0
  • Cedar Gate/EZ-NET portaldescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.