CVEFinder.io

CVE-2022-26483

🔶 medium
🔍 Scan for this CVE
Summary

An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2 Patch 600 and 8.x before 8.0.0 Patch 100. A reflected cross-site scripting (XSS) vulnerability in admin/cgi-bin/listdir.pl allows authenticated remote administrators to inject arbitrary web script or HTML into an HTTP GET parameter (which reflect the user input without sanitization).

CVSS Score
4.8
Medium
EPSS Score
0.2
Exploit Probability
Published Date
2022-03-04
First Seen: 2026-01-05
📊 Relative Risk Intelligence

This CVE is Lower Risk - more severe than 13.8% of all 328,009 vulnerabilities in our database.

#282,765
Below average severity
Severity Percentile
Last Modified 2024-11-21
Source NVD 🔗
CVSS Vector 3.1 CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
CWE IDs (Weakness Types)

📦 Affected Products 2

🔗 References 1

🔗 Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2026-44923 🔶 medium 6.5 0.0 SQL injection in InfoScale VIOM before v9.1.3 allows remote attackers to escalate privileges. 2026-05-20
CVE-2026-44924 🔶 medium 5.4 0.0 InfoScale VIOM 9.1.3 allows XSS. 2026-05-20
CVE-2026-44925 ⚠️ high 8.8 0.0 Cross-Site Request Forgery (CSRF) vulnerability in InfoScale v.9.1.3 Operations Manager (VIOM) allows an attacker to for... 2026-05-20
CVE-2023-38404 ⚠️ high 7.2 0.1 The XPRTLD web application in Veritas InfoScale Operations Manager (VIOM) before 8.0.0.410 allows an authenticated attac... 2023-07-17
CVE-2023-32568 ⚠️ high 7.2 0.3 An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2.800 and 8.x before 8.0.410. The VIOM... 2023-05-10
CVE-2023-32569 ⚠️ high 7.2 0.3 An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2.800 and 8.x before 8.0.410. The Info... 2023-05-10
These CVEs affect the same products