CVE Published: 28/09/2022 |
CVE Updated: 03/08/2024 |
CVE Year: 2022 Source: CERTVDE |
Vendor: Carlo Gavazzi |
Product: UWP 3.0 Monitoring Gateway and Controller Status : PUBLISHED
CVE-2022-28816 Description
In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 the Sentilo Proxy is prone to reflected XSS which only affects the Sentilo service.
Metrics
CVSS Version: 3.1 |
Base Score: 6.1 MEDIUM Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N