cvedb.io
CVE-2022-37318
HIGH · CVSS 7
EPSS exploitation probability: 0%
Published 2022-08-25T23:15:08.557 · Last modified 2026-06-17T04:54:52.727

Summary

Archer Platform 6.9 SP2 P2 before 6.11 P3 (6.11.0.3) contain a reflected XSS vulnerability. A remote unauthenticated malicious Archer user could potentially exploit this vulnerability by tricking a victim application user into supplying malicious JavaScript code to the vulnerable web application. This code is then reflected to the victim and gets executed by the web browser in the context of the vulnerable web application. 6.10 P4 (6.10.0.4) and 6.11 P2 HF4 (6.11.0.2.4) are also fixed releases.

Affected products

rsa — archer

Does this affect you?

Add your gear to cvedb and we'll alert you only when rsa ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.