CVE-2022-44629

CVSS 3.1 Score 4.8 of 10 (medium)

Details

Published Aug 10, 2023
Updated: Aug 11, 2023
CWE ID 79

Summary

CVE-2022-44629 refers to a stored Cross-Site Scripting (XSS) vulnerability affecting the Catalyst Connect plugin, version 2.0.0 and below, of the Zoho CRM Client Portal. An admin user could exploit this flaw by injecting malicious scripts into the input fields of the affected application. Successful attacks could result in unauthorized access to user data or session hijacking. It is crucial for users to update their plugins to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share