PoC Index

CVE-2022-47870

MEDIUM 6.1EPSS 2.2%

A Cross Site Scripting (XSS) vulnerability in the web SQL monitor login page in Redgate SQL Monitor 12.1.31.893 allows remote attackers to inject arbitrary web Script or HTML via the returnUrl parameter.

CVSS v3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS v3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
2.23% chance of exploitation in the next 30 days, 82th percentile
Published
2023-04-04
Updated
2025-02-14

Proof-of-concept exploits (1)

ExploitDB entries (1)

References

Related