Back to search
CVE-2022-22944
Published: Mar 2, 2022
Modified: Aug 3, 2024
PUBLISHED
Description
VMware Workspace ONE Boxer contains a stored cross-site scripting (XSS) vulnerability. Due to insufficient sanitization and validation, in VMware Workspace ONE Boxer calendar event descriptions, a malicious actor can inject script tags to execute arbitrary script within a user's window.
| Vendor | Product | Versions |
|---|---|---|
n/a | VMware Workspace ONE Boxer | affected VMware Workspace ONE Boxer for iOS prior to 22.02 |
References
https://www.vmware.com/security/advisories/VMSA-2022-0006.html
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now