CVE-2022-39035

Publication date

2022-09-28 03:25:40

Family

twcert

State

PUBLISHED

Description

Smart eVision has insufficient filtering for special characters in the POST Data parameter in the specific function. An unauthenticated remote attacker can inject JavaScript to perform XSS (Stored Cross-Site Scripting) attack.