CVE-2022-21146 MEDIUM

CVE-2022-21146: ICSA-22-062-01 IPCOMM ipDIO

Vendor Ipcomm
Product IPCOMM ipDIO
Weakness CWE-79 · XSS
Published March 9, 2022
Last update April 16, 2025

CVSS base score

6.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

What the vulnerability does

01Description

Persistent cross-site scripting in the web interface of ipDIO allows an unauthenticated remote attacker to introduce arbitrary JavaScript by injecting an XSS payload into a specific parameter. The XSS payload will be executed when a legitimate user attempts to review history.

Key dates

02Disclosure timeline

March 9, 2022 CVE published
April 16, 2025 Record updated