imPC@ndo IT

Tracker / CVE-2022-31655

CVE-2022-31655

Medium 5.4

VMware vRealize Log Insight in versions prior to 8.8.2 contain a stored cross-site scripting vulnerability due to improper input sanitization in alerts.

Affected products and versions

vmware vrealize_log_insight · … → 8.8.2

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References