CVE-2022-39024
U-Office Force Bulletin function has insufficient filtering for special characters. An unauthenticated remote attacker c
U-Office Force Bulletin function has insufficient filtering for special characters. An unauthenticated remote attacker can exploit this vulnerability to inject JavaScript and perform XSS (Reflected Cross-Site Scripting) attack.
MEDIUM · CVSS 6.1
EPSS 0.00644
Schedule remediation
- SSVC automatable: yes - attacks can be scripted at scale
Sigma rules0
YARA rules0