CVE-2022-46823 CRITICAL

CVE-2022-46823

Vendor Siemens
Product Mendix SAML (Mendix 8 compatible)
Weakness CWE-79 · XSS
Published January 10, 2023
Last update April 9, 2025

CVSS base score

9.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N/E:P/RL:O/RC:C

What the vulnerability does

01Description

A vulnerability has been identified in Mendix SAML (Mendix 8 compatible) (All versions >= V2.3.0 < V2.3.4), Mendix SAML (Mendix 9 compatible, New Track) (All versions >= V3.3.0 < V3.3.9), Mendix SAML (Mendix 9 compatible, Upgrade Track) (All versions >= V3.3.0 < V3.3.8). The affected module is vulnerable to reflected cross-site scripting (XSS) attacks. This could allow an attacker to extract sensitive information by tricking users into accessing a malicious link.

Key dates

02Disclosure timeline

January 10, 2023 CVE published
April 9, 2025 Record updated

Related vulnerabilities

04Related CVE