CVE-2022-50802

ETAP Safety Manager 1.0.0.32 contains a cross-site scripting vulnerability in the 'action' GET parameter that allows unauthenticated attackers to inject malicious HTML and JavaScript. Attackers can craft specially formed requests to execute arbitrary scripts in victim browser sessions, potentially stealing credentials or performing unauthorized actions.
Configurations

Configuration 1 (hide)

cpe:2.3:a:etaplighting:etap_safety_manager:1.0.0.32:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-12-30 23:15

Updated : 2026-01-07 22:02


NVD link : CVE-2022-50802

Mitre link : CVE-2022-50802

CVE.ORG link : CVE-2022-50802


JSON object : View

Products Affected

etaplighting

  • etap_safety_manager
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')