Medium severity6.3NVD Advisory· Published Feb 3, 2023· Updated Jun 17, 2026
CVE-2022-42908
CVE-2022-42908
Description
WEPA Print Away is vulnerable to a stored XSS. It does not properly sanitize uploaded filenames, allowing an attacker to deceive a user into uploading a document with a malicious filename, which will be included in subsequent HTTP responses, allowing a stored XSS to occur. This attack is persistent across victim sessions.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:wepanow:print_away:-:*:*:*:*:*:*:*
(expand)+ 1 more
- (no CPE)
- (no CPE)range: not versioned
Patches
Vulnerability mechanics
References
2- enrique.wtf/CVE-2022-42908nvdThird Party Advisory
- www.incibe-cert.es/en/early-warning/security-advisories/multiple-vulnerabilities-wepa-print-awaynvdThird Party Advisory
News mentions
0No linked articles in our index yet.